Apache

Druid

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.76%
  • Veröffentlicht 20.03.2025 11:29:00
  • Zuletzt bearbeitet 14.07.2025 12:58:48

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This iss...

  • EPSS 1.17%
  • Veröffentlicht 17.09.2024 19:15:28
  • Zuletzt bearbeitet 14.03.2025 20:15:13

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and d...

  • EPSS 0.3%
  • Veröffentlicht 17.09.2024 19:15:28
  • Zuletzt bearbeitet 14.03.2025 15:15:42

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of al...

  • EPSS 7.19%
  • Veröffentlicht 07.07.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:33

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.

  • EPSS 2.24%
  • Veröffentlicht 07.07.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:08

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

  • EPSS 93.21%
  • Veröffentlicht 24.09.2021 10:15:07
  • Zuletzt bearbeitet 21.11.2024 06:14:00

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privil...

  • EPSS 3.21%
  • Veröffentlicht 02.07.2021 08:15:08
  • Zuletzt bearbeitet 21.11.2024 05:57:02

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privil...

  • EPSS 82.39%
  • Veröffentlicht 30.03.2021 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:57:02

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, wh...

Exploit
  • EPSS 94.06%
  • Veröffentlicht 29.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:55:12

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it ...

  • EPSS 15.57%
  • Veröffentlicht 01.04.2020 22:15:17
  • Zuletzt bearbeitet 21.11.2024 05:11:44

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with ...