logo

Vulnerability details for CVE-2021-25646 

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it ...

CVSS Score (Vector) 9.0 (AV:N/AC:L/Au:S/C:C/I:C/A:C)
ThreatWorx Rating 5 - Urgent
Weakness Types Code Execution, Deserialization of Untrusted Data
Reported By Open Source, GitHub, Security Research, PacketStorm, Red Hat
First Reported Jan 29, 2021 by Open Source
Last Updated Jul 12, 2022 by NVD
NVD Status Published CVE-2021-25646
Affected Products 7 affected product(s) reported by Open Source, GitHub, Security Research, Red Hat
Patches No known patches
Remediations 3 remediation(s) published by Open Source, GitHub
Latest Reference NVD