Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Users should upgrade to Druid 0.20.1. Whenever possible, network access to cluster machines should be restricted to trusted hosts only.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wrqf-rrrw-w3mg | Code injection in Apache Druid |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:49.264Z
Reserved: 2021-01-21T00:00:00.000Z
Link: CVE-2021-25646
No data.
Status : Modified
Published: 2021-01-29T20:15:12.997
Modified: 2024-11-21T05:55:12.470
Link: CVE-2021-25646
OpenCVE Enrichment
No data.
Github GHSA