CVE-2021-44791
published 2022-07-07CVE-2021-44791: In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.09%
79.6th percentile
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | druid | <= 0.22.1 | — |
| apache_software_foundation | apache_druid | Apache Druid – 0.22.1 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
osv·2022-07-08
CVE-2021-44791 [MEDIUM] Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. This issue is patched in version 0.23.0.
GHSA
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
ghsa·2022-07-08
CVE-2021-44791 [MEDIUM] CWE-79 Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks. This issue is patched in version 0.23.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-07
Published