HIGH

CVE-2021-25646

CVSS v3

8.8

HIGH

EPSS Score

94.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

Technical details

Published
1/29/2021

Frequently asked questions

What is CVE-2021-25646?

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

Is CVE-2021-25646 actively exploited?

Active exploitation of CVE-2021-25646 has not been confirmed. The EPSS score is 94.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-25646?

CVE-2021-25646 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2021-25646 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.