PT-2021-17176 · Apache+1 · Apache Druid+1

Fantasyc4T From

+1

·

Published

2021-03-30

·

Updated

2024-10-01

·

CVE-2021-26919

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Druid versions prior to 0.20.2
Description: The issue allows an attacker to execute arbitrary code from a malicious MySQL server within Druid server processes due to certain properties in the MySQL JDBC driver. This functionality is intended for trusted users to set up lookups or submit ingestion tasks using JDBC to read data from other database systems.
Recommendations: For versions prior to 0.20.2, update to Apache Druid 0.20.2 to address the issue. As a temporary workaround, consider restricting access to the MySQL JDBC driver properties to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2021-26919
GHSA-JJ4F-P7VV-J4V9

Affected Products

Apache Druid
Mysql Server