Known Vulnerabilities for Druid by Apache
Listed below are 7 of the newest known vulnerabilities associated with "Druid" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-7468 json | A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file... | Not Provided | 2026-04-30 | 2026-04-30 |
| CVE-2022-28889 json | In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and late... | 4.3 - MEDIUM | 2022-07-07 | 2022-07-15 |
| CVE-2021-44791 json | In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTM... | 6.1 - MEDIUM | 2022-07-07 | 2022-07-15 |
| CVE-2021-36749 json | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSo... | 6.5 - MEDIUM | 2021-09-24 | 2023-11-07 |
| CVE-2021-26920 json | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSo... | 6.5 - MEDIUM | 2021-07-02 | 2023-11-07 |
| CVE-2021-26919 json | Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users w... | 8.8 - HIGH | 2021-03-30 | 2023-11-07 |
| CVE-2021-25646 json | Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functi... | 8.8 - HIGH | 2021-01-29 | 2023-11-07 |
| CVE-2020-1958 json | When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can by... | 6.5 - MEDIUM | 2020-04-01 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Druid | 0.9.2 | |||
| Application | Apache | Druid | 0.9.2 | |||
| Application | Apache | Druid | 0.9.2 | |||
| Application | Apache | Druid | 0.9.2 | |||
| Application | Apache | Druid | 0.9.1.1 | |||
| Application | Apache | Druid | 0.9.1 | |||
| Application | Apache | Druid | 0.9.1 | |||
| Application | Apache | Druid | 0.9.1 | |||
| Application | Apache | Druid | 0.9.1 | |||
| Application | Apache | Druid | 0.9.1 | |||
| Application | Apache | Druid | 0.9.0 | |||
| Application | Apache | Druid | 0.9.0 | |||
| Application | Apache | Druid | 0.9.0 | |||
| Application | Apache | Druid | 0.9.0 | |||
| Application | Apache | Druid | 0.8.3 | |||
| Application | Apache | Druid | 0.8.3 | |||
| Application | Apache | Druid | 0.8.3 | |||
| Application | Apache | Druid | 0.8.3 | |||
| Application | Apache | Druid | 0.8.3 | |||
| Application | Apache | Druid | 0.8.3 |