CVE-2021-36749 describes a local file inclusion vulnerability in Apache Druid's ingestion system, specifically within the HTTP InputSource. Authenticated users can exploit this to read local files on the Druid server with the server process's privileges, bypassing application-level restrictions. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and can lead to high confidentiality impact, though it does not affect integrity or availability. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detection, and its high EPSS score indicates a significant likelihood of future exploitation. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.22.0CPE matchmatch criteria | cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.