CVE-2021-25646 is a critical remote code execution (RCE) vulnerability affecting Apache Druid versions 0.20.0 and earlier. An authenticated attacker can exploit this flaw by sending a specially crafted request that forces Druid to execute arbitrary JavaScript code, even if JavaScript execution is disabled by default. This allows for code execution on the target machine with the privileges of the Druid server process. The vulnerability has a CVSS score of 8.8 (HIGH) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not on the KEV catalog, exploit modules are publicly available in Metasploit and Nuclei, and there is community discussion indicating active interest in exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.20.0CPE matchmatch criteria | cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.