Apache Doris MCP Server: SQL injection leading the authentication bypass (CVE-2025-66336) | HOL Guard CVE