Security for everyone

CVE-2021-25646 Scanner

Detects 'Code Injection' vulnerability in Apache Druid affects v. 0.20.0 and earlier.

SCAN NOW

Short Info


Level

High

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

30 sec

Scan only one

Url

Parent Category

CVE-2021-25646 Scanner Detail

Apache Druid is a data store that was built to meet the needs of large-scale, real-time analytics. It allows users to manage data sets in a distributed and scalable way, providing fast querying and analysis capabilities. The platform is used by businesses across various industries to support real-time data ingestion and queries, operational monitoring, and machine learning use cases.

However, recently, a security vulnerability has been detected in the platform, known as CVE-2021-25646. This vulnerability makes it possible for any authenticated user to send a specially crafted request that forces Druid to execute user-provided JavaScript code for that request, regardless of server configuration. As a result, an attacker can exploit this vulnerability to execute code on the target server with the privileges of the Druid server process, which can lead to a range of malicious activities.

When this vulnerability is exploited, an attacker can gain access to sensitive data, including user credentials and intellectual property. They can install malware or ransomware on the server and take control of the system. Furthermore, they can use the compromised server to launch attacks on other systems, escalating the severity of the breach and causing significant harm to the organization.

Thanks to the pro features of the securityforeveryone.com platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The website provides comprehensive vulnerability scanning and management to help organizations stay on top of cyber threats. By using the platform, businesses can ensure that their systems remain secure and are protected against the latest threats.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture