Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-45384
Apache Druid: padding oracle in the druid-pac4j extension
Technology
Apache Druid
CVSS Score
5.3 / 10.0
Affected Versions
Apache Druid 0.18.0 to 30.0.0, with druid-pac4j
Upstream Fix
30.0.1
Published
September 17, 2024
OSSeva Coverage
Fixed upstream
Description
A padding oracle in the optional druid-pac4j extension could let an attacker manipulate a pac4j session cookie. The extension is disabled by default. The advisory says no meaningful exploit is known and recommends a strong druid.auth.pac4j.cookiePassphrase as a precaution.
Is your Apache Druid deployment affected?
If you're running Apache Druid 0.18.0 to 30.0.0, with druid-pac4j, you need this patch. Book a discovery call to get covered.