GHSA-8rmv-98m4-g5c6
Dashboard / Vulnerabilities / GHSA-8rmv-98m4-g5c6
Summary: Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
Details: In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. This issue is patched in version 0.23.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-44791, https://github.com/apache/druid, https://lists.apache.org/thread/lh2kcl4j45q7xj4w6rqf6kwf0mvyp2o6
Affected packages
Package
Name: org.apache.druid:druid
Purl: pkg:maven/org.apache.druid/druid
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.23.0
Affected versions
0.13.0-incubating
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
