Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-45537
Apache Druid: MySQL JDBC connection strings bypass the allowed properties list
Technology
Apache Druid
CVSS Score
6.5 / 10.0
Affected Versions
Apache Druid through 30.0.0
Upstream Fix
30.0.1
Published
September 17, 2024
OSSeva Coverage
Fixed upstream
Description
Druid limits the JDBC properties users can set for lookups and ingestion to an allow list, TLS-related properties by default, but a crafted MySQL JDBC connection string can set properties outside it. Only users permitted to configure JDBC connections can exploit it. It follows CVE-2021-26919, which 0.20.2 addressed only in part.
Is your Apache Druid deployment affected?
If you're running Apache Druid through 30.0.0, you need this patch. Book a discovery call to get covered.