Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpqNGYtcDd2di1qNHY5

Arbitrary code execution in Apache Druid

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Druid server processes. This issue was addressed in Apache Druid 0.20.2

Permalink: https://github.com/advisories/GHSA-jj4f-p7vv-j4v9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpqNGYtcDd2di1qNHY5
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 3 years ago
Updated: about 1 year ago


CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-jj4f-p7vv-j4v9, CVE-2021-26919
References: Repository: https://github.com/apache/druid
Blast Radius: 0.0

Affected Packages

maven:org.apache.druid:druid
Dependent packages: 1
Dependent repositories: 1
Downloads:
Affected Version Ranges: < 0.20.2
Fixed in: 0.20.2
All affected versions: 0.17.0, 0.17.1, 0.18.0, 0.18.1, 0.19.0, 0.20.0, 0.20.1
All unaffected versions: 0.20.2, 0.21.0, 0.21.1, 0.22.0, 0.22.1, 0.23.0, 24.0.0, 24.0.1, 24.0.2, 25.0.0, 26.0.0, 27.0.0, 28.0.0, 28.0.1, 29.0.0