Back to Vulnerability Directory
HIGHFixed upstream
CVE-2021-25646
Apache Druid: authenticated users can force JavaScript execution
Technology
Apache Druid
CVSS Score
8.8 / 10.0
Affected Versions
Apache Druid 0.20.0 and earlier
Upstream Fix
0.20.1
Published
January 29, 2021
OSSeva Coverage
Fixed upstream
Description
Druid can run user-supplied JavaScript embedded in requests, a feature disabled by default. In 0.20.0 and earlier, an authenticated user can send a crafted request that forces Druid to run JavaScript regardless of server configuration, executing code with the privileges of the Druid process.
Is your Apache Druid deployment affected?
If you're running Apache Druid 0.20.0 and earlier, you need this patch. Book a discovery call to get covered.