No analysis available yet.
Vendor Workaround
Users should upgrade to Druid 0.20.1. Whenever possible, network access to cluster machines should be restricted to trusted hosts only.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wrqf-rrrw-w3mg | Code injection in Apache Druid |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:49.264Z
Reserved: 2021-01-21T00:00:00.000Z
Link: CVE-2021-25646
No data.
Status : Modified
Published: 2021-01-29T20:15:12.997
Modified: 2026-06-17T03:42:16.333
Link: CVE-2021-25646
OpenCVE Enrichment
No data.
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
- NVD-CWE-noinfo
Github GHSA