Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2021-36749

Apache Druid: HTTP input source reads local files (incomplete fix of CVE-2021-26920)

Technology

Apache Druid

CVSS Score

6.5 / 10.0

Affected Versions

Apache Druid through 0.21.1

Upstream Fix

0.22.0

Published

September 24, 2021

OSSeva Coverage

Fixed upstream

Description

The HTTP input source lets authenticated users read from sources other than intended, such as the local file system, with the privileges of the Druid process. This matters where users reach Druid through an application that allows the HTTP input source but not the Local input source. The fix announced for 0.21.0 under CVE-2021-26920 was not effective in 0.21.0 or 0.21.1.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid through 0.21.1, you need this patch. Book a discovery call to get covered.