Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Users can avoid the issue by upgrading to 0.22.0 or a higher version. In an earlier version than 0.22.0, when the user application wants to restrict the access to the local file system, it should disallow all InputSources that can read local files, that is the Local, HTTP, and HDFS InputSources.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9p5g-vg43-mj5r | Druid ingestion system Authenticated users can read data from other sources than intended |
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T01:01:59.216Z
Reserved: 2021-07-15T00:00:00.000Z
Link: CVE-2021-36749
No data.
Status : Modified
Published: 2021-09-24T10:15:07.257
Modified: 2024-11-21T06:14:00.913
Link: CVE-2021-36749
OpenCVE Enrichment
No data.
Github GHSA