Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2021-36749
Apache Druid: HTTP input source reads local files (incomplete fix of CVE-2021-26920)
Technology
Apache Druid
CVSS Score
6.5 / 10.0
Affected Versions
Apache Druid through 0.21.1
Upstream Fix
0.22.0
Published
September 24, 2021
OSSeva Coverage
Fixed upstream
Description
The HTTP input source lets authenticated users read from sources other than intended, such as the local file system, with the privileges of the Druid process. This matters where users reach Druid through an application that allows the HTTP input source but not the Local input source. The fix announced for 0.21.0 under CVE-2021-26920 was not effective in 0.21.0 or 0.21.1.
Is your Apache Druid deployment affected?
If you're running Apache Druid through 0.21.1, you need this patch. Book a discovery call to get covered.