https://seclists.org/oss-sec/2024/q3/259: CVE-2024-45384: Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack
Published Sep 17, 2024
·Updated
Affected Software
1 affected component
Apache Druid>=0.18.0<30.0.0
Frequently Asked Questions
1
What is the severity of CVE-2024-45384?
The severity of CVE-2024-45384 is classified as low.
2
What versions of Apache Druid are affected by CVE-2024-45384?
Apache Druid versions 0.18.0 through 30.0.0 are affected by CVE-2024-45384.
3
How can I fix CVE-2024-45384?
To fix CVE-2024-45384, upgrade Apache Druid to a version higher than 30.0.0.
4
What type of attack does CVE-2024-45384 allow?
CVE-2024-45384 allows an attacker to perform a Padding Oracle Attack to manipulate a pac4j session cookie.
5
Is there a workaround for CVE-2024-45384?
Currently, there are no documented workarounds for CVE-2024-45384 other than upgrading to a fixed version.