'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2021-25646: Apache Druid Remote Code Execution Vulnerability
Severity:high
CVE ID:CVE-2021-25646
Descripiton:
|
Apache Druid is a column-oriented open source distributed database written in the Java language by the Apache Foundation of the United States.Apache Druid 0.20.0 and earlier versions have an access control error vulnerability, which allows an authenticated user to force Druid to run user-supplied JavaScript code and execute code that is privileged by the server process. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.