Security researcher finds three critical flaws in Apache Doris, Alibaba RDS, and Apache Pinot databases

theregister.com

Three serious vulnerabilities were found in MCP database servers, with one remaining unpatched. The flaws affect Apache Doris, Alibaba RDS, and Apache Pinot, potentially allowing SQL injection, data exfiltration, and database takeover. Alibaba declined to patch its vulnerability. These issues highlight broader security concerns in MCP server development, with experts warning of more vulnerabilities to come if security practices are not improved.


With a significance score of 3.5, this news ranks in the top 7% of today's 30296 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Security researcher finds three critical flaws in Apache Doris, Alibaba RDS, and Apache Pinot databases | News Minimalist