Количество 3
Количество 3
CVE-2026-23906
Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials. The vulnerability stems from improper validation of LDAP authentication r
CVE-2026-23906
Affected Products and Versions * Apache Druid * Affected Version ...
GHSA-q672-hfc7-g833
Apache Druid Vulnerable to Authentication Bypass
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind Vulnerability Description An authentication bypass vulnerability exists in Apache Druid when using the druid-basic-security extension with LDAP authentication. If the underlying LDAP server is configured to allow anonymous binds, an attacker can bypass authentication by providing an existing username with an empty password. This allows unauthorized access to otherwise restricted Druid resources without valid credentials. The vulnerability stems from improper validation of LDAP authentication r | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Version ... | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-q672-hfc7-g833 Apache Druid Vulnerable to Authentication Bypass | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу