← back
CVE-2021-25646observed exploitation

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 99%
from disclosure to weapon5 days
Published on NVDJan 29
1st PoC+5d
metasploitJan 21
VulnCheck+1018d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.