CVE-2021-25646

HIGH EXPLOITED IN THE WILD NUCLEI

Apache Druid <0.20.0 - XSS

Title source: llm

Description

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

Exploits (13)

nomisec WRITEUP 1,079 stars
by 1n7erface · poc
https://github.com/1n7erface/PocList
nomisec WORKING POC 17 stars
by yaunsky · remote
https://github.com/yaunsky/cve-2021-25646
nomisec WORKING POC 5 stars
by k7pro · remote
https://github.com/k7pro/CVE-2021-25646-exp
nomisec WORKING POC 4 stars
by j2ekim · remote
https://github.com/j2ekim/CVE-2021-25646
nomisec SUSPICIOUS 3 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/Apache-Druid-CVE-2021-25646
nomisec SCANNER 3 stars
by givemefivw · poc
https://github.com/givemefivw/CVE-2021-25646
nomisec WORKING POC 2 stars
by lp008 · poc
https://github.com/lp008/CVE-2021-25646
nomisec WORKING POC 1 stars
by Ormicron · poc
https://github.com/Ormicron/CVE-2021-25646-GUI
gitlab WORKING POC
by bybsecs · poc
https://gitlab.com/bybsecs/cve-2021-25646
nomisec WORKING POC
by ShadowLance2 · remote
https://github.com/ShadowLance2/Apache-Druid-CVE-2021-25646-Exploit
nomisec WORKING POC
by tiemio · remote
https://github.com/tiemio/RCE-PoC-CVE-2021-25646
nomisec WORKING POC
by gps1949 · remote
https://github.com/gps1949/CVE-2021-25646
metasploit WORKING POC EXCELLENT
by Litch1, Security Team of Alibaba Cloud, je5442804 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_druid_js_rce.rb

Nuclei Templates (1)

Apache Druid - Remote Code Execution
HIGHby pikpikcu

References (16)

Scores

CVSS v3 8.8
EPSS 0.9397
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-13
InTheWild.io 2024-05-29
Status published
Products (2)
apache/druid < 0.20.0
org.apache.druid/druid 0 - 0.20.1Maven
Published Jan 29, 2021
Tracked Since Feb 18, 2026