Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-26919

Apache Druid: code execution from a malicious MySQL server through JDBC properties

Technology

Apache Druid

CVSS Score

8.8 / 10.0

Affected Versions

Apache Druid through 0.20.1

Upstream Fix

0.20.2

Published

March 30, 2021

OSSeva Coverage

Fixed upstream

Description

Druid lets trusted users read from other databases over JDBC for lookups and ingestion. Certain MySQL JDBC driver properties, left unmitigated, let an attacker run code inside Druid server processes from a malicious MySQL server under their control.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid through 0.20.1, you need this patch. Book a discovery call to get covered.