Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-45384

Apache Druid: padding oracle in the druid-pac4j extension

Technology

Apache Druid

CVSS Score

5.3 / 10.0

Affected Versions

Apache Druid 0.18.0 to 30.0.0, with druid-pac4j

Upstream Fix

30.0.1

Published

September 17, 2024

OSSeva Coverage

Fixed upstream

Description

A padding oracle in the optional druid-pac4j extension could let an attacker manipulate a pac4j session cookie. The extension is disabled by default. The advisory says no meaningful exploit is known and recommends a strong druid.auth.pac4j.cookiePassphrase as a precaution.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid 0.18.0 to 30.0.0, with druid-pac4j, you need this patch. Book a discovery call to get covered.