MEDIUM🇵🇱 Wersja polska

CVE-2025-27888

CVSS 5.8v4.0pub. 2025-03-20upd. 2025-07-14

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected. Users are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Apache Druid

    APP
    Apache
    < 31.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSSSRF
CWE
References

Related vulnerabilities

CVE-2026-23906CRITICAL9.8PL ✓same product

Apache Druid – pominięcie uwierzytelnienia LDAP przez anonimowy bind

CVE-2025-59390CRITICAL9.8PL ✓same product

Apache Druid: słaby generator losowy umożliwia bypass uwierzytelnienia Kerberos

CVE-2021-26919HIGH8.8same product

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow ...

CVE-2021-25646HIGH8.8same product

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of reques...

CVE-2024-45384MEDIUM5.3same product

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulat...