Описание
Affected Products and Versions
- Apache Druid
- Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
- Prerequisites: * druid-basic-security extension enabled
- LDAP authenticator configured
- Underlying LDAP server permits anonymous bind
Vulnerability Description
An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials.
The vulnerability stems from improper validation of LDAP authentication r
Ссылки
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.17.0 (включая) до 36.0.0 (исключая)
cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
debian
около 2 месяцев назад
Affected Products and Versions * Apache Druid * Affected Version ...
EPSS
Процентиль: 25%
0.00085
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287