Apache

Druid

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.76%
  • Published 20.03.2025 11:29:00
  • Last modified 14.07.2025 12:58:48

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This iss...

  • EPSS 1.17%
  • Published 17.09.2024 19:15:28
  • Last modified 14.03.2025 20:15:13

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and d...

  • EPSS 0.3%
  • Published 17.09.2024 19:15:28
  • Last modified 14.03.2025 15:15:42

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows administrators to configure a list of al...

  • EPSS 7.19%
  • Published 07.07.2022 19:15:07
  • Last modified 21.11.2024 06:31:33

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.

  • EPSS 2.24%
  • Published 07.07.2022 19:15:07
  • Last modified 21.11.2024 06:58:08

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

  • EPSS 93.21%
  • Published 24.09.2021 10:15:07
  • Last modified 21.11.2024 06:14:00

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privil...

  • EPSS 3.21%
  • Published 02.07.2021 08:15:08
  • Last modified 21.11.2024 05:57:02

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privil...

  • EPSS 82.39%
  • Published 30.03.2021 08:15:11
  • Last modified 21.11.2024 05:57:02

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, wh...

Exploit
  • EPSS 94.06%
  • Published 29.01.2021 20:15:12
  • Last modified 21.11.2024 05:55:12

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it ...

  • EPSS 15.57%
  • Published 01.04.2020 22:15:17
  • Last modified 21.11.2024 05:11:44

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with ...