Druid には、不正な認証に関する脆弱性が存在します。
Apache Software Foundation Apache Druid
本脆弱性の影響を受ける製品の詳細については、ベンダ情報および参考情報をご確認ください。
情報を取得される可能性があります。
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。
Apache Software Foundation Pony Mail : CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended Pony Mail : CVE-2021-36749: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) Pony Mail : CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended Pony Mail : CVE-2021-36749: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
不正な認証(CWE-863) [NVD評価]
CVE-2021-26920
National Vulnerability Database (NVD) : CVE-2021-26920 関連文書 : CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended 関連文書 : CVE-2021-36749: Apache Druid: The HTTP inputSource allows
[2022年03月24日] 掲載