PT-2020-15191 · Apache · Apache Druid

Published

2020-04-01

·

Updated

2022-04-06

·

CVE-2020-1958

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Druid version 0.17.0
Description The issue allows callers of Druid APIs with valid LDAP credentials to bypass the credentialsValidator.userSearch filter, which determines if a valid LDAP user can authenticate with Druid. Although role-based authorization checks still apply if configured, callers can also retrieve any visible LDAP attribute values of users on the LDAP server without needing to be a valid LDAP user themselves.
Recommendations For Apache Druid version 0.17.0, consider disabling LDAP authentication until a patch is available to prevent bypassing the credentialsValidator.userSearch filter and unauthorized retrieval of LDAP attribute values. Restrict access to Druid APIs to minimize the risk of exploitation. Avoid using the credentialsValidator.userSearch filter in the affected API endpoints until the issue is resolved.

Exploit

Fix

Special Elements Injection

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1958
GHSA-QH2G-7H5P-MXF4

Affected Products

Apache Druid