PT-2021-17176 · Apache+1 · Apache Druid+1
Fantasyc4T From
+1
·
Published
2021-03-30
·
Updated
2024-10-01
·
CVE-2021-26919
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Druid versions prior to 0.20.2
Description:
The issue allows an attacker to execute arbitrary code from a malicious MySQL server within Druid server processes due to certain properties in the MySQL JDBC driver. This functionality is intended for trusted users to set up lookups or submit ingestion tasks using JDBC to read data from other database systems.
Recommendations:
For versions prior to 0.20.2, update to Apache Druid 0.20.2 to address the issue. As a temporary workaround, consider restricting access to the MySQL JDBC driver properties to minimize the risk of exploitation.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Druid
Mysql Server