QID 982229
QID 982229: Java (maven) Security Update for org.apache.druid:druid (GHSA-jj4f-p7vv-j4v9)
Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Druid server processes. This issue was addressed in Apache Druid 0.20.2
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jj4f-p7vv-j4v9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-jj4f-p7vv-j4v9 -
github.com/advisories/GHSA-jj4f-p7vv-j4v9
CVEs related to QID 982229
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jj4f-p7vv-j4v9 | org.apache.druid:druid |
|