S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-36749 Scanner

CVE-2021-36749 scanner - Improper Access Control vulnerability in Apache Druid

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-36749
6.5
CVSS

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource. This issue was previously mentioned as being fixed in 0.21.0 as per CVE-2021-26920 but was not fixed in 0.21.0 or 0.21.1.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Druidby Apache Software Foundation
0.21.1 and earlier
Updated Aug 21, 2026View on NVD →
Detail

Apache Druid is an open-source data store designed for fast OLAP queries using a column-oriented data layout and advanced indexing options. It is intended to be faster and more scalable than traditional relational databases, capable of handling streaming data in real-time. Druid is particularly useful for use cases like time series data, where the data that is coming through an ingestion pipeline goes through an iterative process of incremental updates and queries. Druid provides a robust ingestion system that can handle the difficult problem of moving high volumes of data, including time-series data, from various sources into Druid.

The CVE-2021-36749 vulnerability detected in Apache Druid is related to the HTTP InputSource, which is used to read data from various sources. The issue is that authenticated users can use the HTTP InputSource to read data from unintended sources such as the local file system, with the privileges of the Druid server process. This could lead to serious security issues if attackers use this vulnerability to bypass application-level restrictions by passing a file URL to the HTTP InputSource. If the affected version of Druid is integrated with an application that allows users to specify the HTTP InputSource but not the Local InputSource, users could exploit this vulnerability to read sensitive data.

Exploitation of this vulnerability could lead to severe consequences for businesses and users of Apache Druid. Attackers could use this vulnerability to access sensitive data, including passwords, confidential documents, and other secrets. They could steal intellectual property, damage reputations, and disrupt business operations. Moreover, they could use the information harvested from Druid to launch further attacks that could compromise the entire infrastructure of the affected system or organization.

Thanks to the pro features of the s4e.io platform, you can easily and quickly learn about any potential vulnerabilities in your digital assets. Our platform provides a comprehensive vulnerability assessment for your applications and infrastructure, including Apache Druid. With regular vulnerability scans, you can stay ahead of the attackers and protect your data from potential breaches. Don't wait until it's too late. Sign up for our platform today and secure your digital assets.

 

REFERENCES

Solution Advice

There are several precautions that you can take to protect against the CVE-2021-36749 vulnerability in Apache Druid. Here is a bullet list of those precautions:

  • Upgrade to the latest version of Apache Druid that fixes the vulnerability.
  • Configure Druid to use non-privileged accounts and limit the scope of access.
  • Implement strong authentication and authorization mechanisms to protect against unauthorized access.
  • Monitor and log all activities related to Druid, including data access and authentication attempts.
  • Perform regular security assessments and vulnerability scans to detect and remediate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.