← back
CVE-2021-25646observed exploitation

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 99%
from disclosure to weapon5 days
Published on NVDJan 29
1st PoC+5d
metasploitJan 21
VulnCheck+1018d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product
Red Hat OpenShift Container Platform 4
no_fix_planned: Will not fix
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.