Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2025-27888
Apache Druid: management proxy open to SSRF, XSS and open redirect
Technology
Apache Druid
CVSS Score
5.4 / 10.0
Affected Versions
Apache Druid before 31.0.2; 32.0.0
Upstream Fix
31.0.2, 32.0.1
Published
March 20, 2025
OSSeva Coverage
Fixed upstream
Description
A specially crafted URL sent through the Druid management proxy can redirect the request to an arbitrary server, with the potential for cross-site scripting or request forgery. The user must be authenticated. The management proxy is enabled out of the box and can be disabled as a mitigation, at the cost of some web console features.
Is your Apache Druid deployment affected?
If you're running Apache Druid before 31.0.2; 32.0.0, you need this patch. Book a discovery call to get covered.