Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-25646

Apache Druid: authenticated users can force JavaScript execution

Technology

Apache Druid

CVSS Score

8.8 / 10.0

Affected Versions

Apache Druid 0.20.0 and earlier

Upstream Fix

0.20.1

Published

January 29, 2021

OSSeva Coverage

Fixed upstream

Description

Druid can run user-supplied JavaScript embedded in requests, a feature disabled by default. In 0.20.0 and earlier, an authenticated user can send a crafted request that forces Druid to run JavaScript regardless of server configuration, executing code with the privileges of the Druid process.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid 0.20.0 and earlier, you need this patch. Book a discovery call to get covered.