Apache
Apache Druid: vulnerabilidades y CVE
Apache Druid tiene 12 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-23906 | Crítica (9.8) | 1.1% | — | 10 feb 2026 | Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow… |
| CVE-2025-59390 | Crítica (9.8) | 0.61% | — | 26 nov 2025 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using… |
| CVE-2025-27888 | Media (5.8) | 1.8% | — | 20 mar 2025 | Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect')… |
| CVE-2024-45537 | Media (6.5) | 0.63% | — | 17 sept 2024 | Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run ingestion tasks. Druid also allows… |
| CVE-2024-45384 | Media (5.3) | 0.82% | — | 17 sept 2024 | Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the… |
| CVE-2022-28889 | Media (4.3) | 1.9% | — | 7 jul 2022 | In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header. |
| CVE-2021-44791 | Media (6.1) | 2.2% | — | 7 jul 2022 | In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. |
| CVE-2021-36749 | Media (6.5) | 81% | — | 24 sept 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the… |
| CVE-2021-26920 | Media (6.5) | 9.5% | — | 2 jul 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the… |
| CVE-2021-26919 | Alta (8.8) | 23% | — | 30 mar 2021 | Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver… |
| CVE-2021-25646 | Alta (8.8) | 99% | — | 29 ene 2021 | Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However,… |
| CVE-2020-1958 | Media (6.5) | 4.6% | — | 1 abr 2020 | When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.