First published: Thu Jul 07 2022(Updated: )
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Druid | <=0.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44791 is a vulnerability in Apache Druid 0.22.1 and earlier versions that allows for reflected XSS attacks through specially-crafted links.
The severity of CVE-2021-44791 is medium, with a CVSS score of 6.1.
CVE-2021-44791 affects Apache Druid 0.22.1 and earlier versions by allowing unescaped URL parameters to be sent back in HTML responses, enabling reflected XSS attacks.
To fix CVE-2021-44791, it is recommended to upgrade to a version of Apache Druid that is not affected by the vulnerability.
More information about CVE-2021-44791 can be found at the following link: [https://lists.apache.org/thread/lh2kcl4j45q7xj4w6rqf6kwf0mvyp2o6]