Sploitus

CVE-2021-25646

17 known exploits for CVE-2021-25646

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

Affected products
Apache Druid
Apache Druid
≤ 0.20.0
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
99.0% (100th percentile)
NVD status
Modified
Published
2021-01-29

Workaround

Users should upgrade to Druid 0.20.1. Whenever possible, network access to cluster machines should be restricted to trusted hosts only.

CVE-2021-25646 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2021-25646

Proof-of-concept code and exploit modules indexed by Sploitus