Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
- EPSS 94.06%
- Veröffentlicht 29.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:55:12
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it ...
6.5
CVE-2020-1958
- EPSS 15.57%
- Veröffentlicht 01.04.2020 22:15:17
- Zuletzt bearbeitet 21.11.2024 05:11:44
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with ...