Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-27888

Apache Druid: management proxy open to SSRF, XSS and open redirect

Technology

Apache Druid

CVSS Score

5.4 / 10.0

Affected Versions

Apache Druid before 31.0.2; 32.0.0

Upstream Fix

31.0.2, 32.0.1

Published

March 20, 2025

OSSeva Coverage

Fixed upstream

Description

A specially crafted URL sent through the Druid management proxy can redirect the request to an arbitrary server, with the potential for cross-site scripting or request forgery. The user must be authenticated. The management proxy is enabled out of the box and can be disabled as a mitigation, at the cost of some web console features.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid before 31.0.2; 32.0.0, you need this patch. Book a discovery call to get covered.