Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 99%
from disclosure to weapon5 days
Published on NVDJan 29
1st PoC+5d
metasploitJan 21
VulnCheck+1018d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
Affected products
Apache Software Foundation · Apache Druidpublic PoCs found — 9
vulncheckvulncheck.com/xdb/90e27828c0bfunverifiedvulncheckvulncheck.com/xdb/762a40d94ce5unverifiedvulncheckvulncheck.com/xdb/ff8ab82ad27aunverifiedvulncheckvulncheck.com/xdb/a235c0567568unverifiedvulncheckvulncheck.com/xdb/9f5a95435985unverifiedvulncheckvulncheck.com/xdb/3b8e94956218unverifiedvulncheckvulncheck.com/xdb/133682477372unverifiedvulncheckvulncheck.com/xdb/df5ffd94ec72unverifiedvulncheckvulncheck.com/xdb/8c7ff756c119unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/162345/Apache-Druid-0.20.0-Remote-Command-Execution.htmlhttps://lists.apache.org/thread.html/r04fa1ba93599487c95a8497044d37f8c02a439bfcf92b4567bfb7c8f%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r121abe8014d381943b63c60615149d40bde9dc1c868bcee90d0d0848%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r20e0c3b10ae2c05a3aad40f1476713c45bdefc32c920b9986b941d8f%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r443e2916c612fbd119839c0fc0729327d6031913a75081adac5b43ad%40%3Cdev.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r4f84b542417ea46202867c0a8b3eaf3b4cfed30e09174a52122ba210%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r5ef625076982aee7d23c23f07717e626b73f421fba5154d1e4de15e1%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r64431c2b97209f566b5dff92415e7afba0ed3bfab4695ebaa8a62e5d%40%3Cdev.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r7dff4790e7a5c697fc0360adf11f5aeb31cd6ad80644fffee690673c%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r87aa94e28dd21ee2252d30c63f01ab9cb5474ee5bdd98dd8d7d734aa%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/ra4225912f501016bc5e0ac44e14b8d6779173a3a1dc7baacaabcc9ba%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc167d5e57f3120578718a7a458ce3e73b3830ac4efbb1b085bd06b92%40%3Cdev.druid.apache.org%3E