Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-45537

Apache Druid: MySQL JDBC connection strings bypass the allowed properties list

Technology

Apache Druid

CVSS Score

6.5 / 10.0

Affected Versions

Apache Druid through 30.0.0

Upstream Fix

30.0.1

Published

September 17, 2024

OSSeva Coverage

Fixed upstream

Description

Druid limits the JDBC properties users can set for lookups and ingestion to an allow list, TLS-related properties by default, but a crafted MySQL JDBC connection string can set properties outside it. Only users permitted to configure JDBC connections can exploit it. It follows CVE-2021-26919, which 0.20.2 addressed only in part.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid through 30.0.0, you need this patch. Book a discovery call to get covered.