← Advisories

Apache OzHera 2.2.6 Authenticated SQL Injection

High
Advisory ID
ZSL-2026-6012
Release Date
08 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
2.2.6-incubating
CVE
N/A
Tested On
Eclipse Temurin OpenJDK 21.0.6 (LTS), H2 in-memory, MySQL mode, Apache Doris
Summary

Apache OzHera(Incubating) is an Application Performance Monitoring (APM) platform designed for the cloud-native era. It revolves around applications and integrates capabilities such as metric monitoring, distributed tracing, logging, and alerting. The platform's mission is to enhance the online stability of applications and enable businesses to detect and locate issues within 1 minute and 5 minutes, respectively, when problems occur.

Description

Apache OzHera is affected by a SQL injection vulnerability in its Doris-backed log search. In EsDataServiceImpl, the log-search query is built by string-interpolating user-supplied request parameters and executed on a plain Statement (createStatement().executeQuery) with no parameterization or escaping, against the Doris log store. The injectable parameters are the full-text search term (fullTextSearch, spliced as a WHERE condition in buildQuerySql and in the statistics path buildQuerySqlConditional), the sort key (sortKey, spliced after ORDER BY), and the tail selector (tail, quoted and spliced into a tail IN (...) clause). Numeric parameters (startTime/endTime/page/pageSize) are not injectable, and Elasticsearch-backed log stores use a different, unaffected code path. An authenticated console user can inject SQL and read data beyond the intended query, including other tables and log stores within the same Doris instance.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
21.08.2026Vendor confirms the vulnerability (master @ 4c0bdb9e). Fix planned for mid-October.
05.10.2026Asked vendor for status update.
07.10.2026No response from the vendor.
08.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
08.10.2026Initial release