Apache OzHera(Incubating) is an Application Performance Monitoring (APM) platform designed for the cloud-native era. It revolves around applications and integrates capabilities such as metric monitoring, distributed tracing, logging, and alerting. The platform's mission is to enhance the online stability of applications and enable businesses to detect and locate issues within 1 minute and 5 minutes, respectively, when problems occur.
Apache OzHera is affected by a SQL injection vulnerability in its Doris-backed log search. In EsDataServiceImpl, the log-search query is built by string-interpolating user-supplied request parameters and executed on a plain Statement (createStatement().executeQuery) with no parameterization or escaping, against the Doris log store. The injectable parameters are the full-text search term (fullTextSearch, spliced as a WHERE condition in buildQuerySql and in the statistics path buildQuerySqlConditional), the sort key (sortKey, spliced after ORDER BY), and the tail selector (tail, quoted and spliced into a tail IN (...) clause). Numeric parameters (startTime/endTime/page/pageSize) are not injectable, and Elasticsearch-backed log stores use a different, unaffected code path. An authenticated console user can inject SQL and read data beyond the intended query, including other tables and log stores within the same Doris instance.