Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2021-44791

Apache Druid: reflected cross-site scripting on some HTTP endpoints

Technology

Apache Druid

CVSS Score

6.1 / 10.0

Affected Versions

Apache Druid 0.22.1 and earlier

Upstream Fix

0.23.0

Published

July 7, 2022

OSSeva Coverage

Fixed upstream

Description

Certain specially crafted links cause Druid to send unescaped URL parameters back in HTML responses, which allows reflected cross-site scripting.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid 0.22.1 and earlier, you need this patch. Book a discovery call to get covered.