PT-2025-12331 · Apache · Apache Druid

Xbow

·

Published

2025-03-19

·

Updated

2025-09-23

·

CVE-2025-27888

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Apache Druid and Affected Versions Apache Druid versions prior to 31.0.2 and prior to 32.0.1
Description Apache Druid is susceptible to Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), and Open Redirect issues. When the Druid management proxy is used, a specially crafted URL in a request can redirect the request to an arbitrary server, potentially leading to XSS or Cross-Site Request Forgery (XSRF). Exploitation requires user authentication. The management proxy is enabled by default in Druid configurations. The issue affects all previous versions of Druid. The vulnerability stems from improper neutralization of input during web page generation and an open redirect vulnerability.
Recommendations Upgrade to Druid version 31.0.2 or 32.0.1 to resolve the issue. As a mitigation, disable the Druid management proxy. Note that disabling the management proxy will affect some web console features, but core functionality will remain operational.

Fix

Open Redirect

SSRF

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-07571
CVE-2025-27888
GHSA-2XCR-P767-F3RV

Affected Products

Apache Druid