Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
Published Sep 24, 2021
6.5
MEDIUMCVSS 3.1
EPSS 80.91%
Description
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource. This issue was previously mentioned as being fixed in 0.21.0 as per CVE-2021-26920 but was not fixed in 0.21.0 or 0.21.1.
Affected products
-
- Version 0.21.1 and earlierStatusaffectedConstraints<=0.21.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Druid | n/a |
|
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hive
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hive | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Users can avoid the issue by upgrading to 0.22.0 or a higher version.
In an earlier version than 0.22.0, when the user application wants to restrict the access to the local file system, it should disallow all InputSources that can read local files, that is the Local, HTTP, and HDFS InputSources.
Red Hat statement
OpenShift Container Platform (OCP) shipped Druid in the ose-metering-hive container, however InputSources such as HTTP and HDFS are not included, hence OCP is not affected by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 80.91% (0.80907) | 99.62th | v5 (v2026.06.15) |
| Jun 15, 2026 | 81.04% (0.81038) | 99.58th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.15% (0.93147) | 99.79th | v4 (v2025.03.14) |
| Feb 27, 2025 | 91.59% (0.91594) | 99.19th | v3 (v2023.03.01) |
| Dec 17, 2024 | 92.84% (0.92838) | 99.25th | v3 (v2023.03.01) |
| Nov 10, 2024 | 75.99% (0.75986) | 98.26th | v3 (v2023.03.01) |
| Oct 27, 2024 | 77.40% (0.77404) | 98.29th | v3 (v2023.03.01) |
| Jul 5, 2024 | 76.24% (0.76238) | 98.20th | v3 (v2023.03.01) |
| Jun 23, 2024 | 75.98% (0.75985) | 98.19th | v3 (v2023.03.01) |
| May 14, 2024 | 75.24% (0.75244) | 98.14th | v3 (v2023.03.01) |
| Apr 30, 2024 | 82.06% (0.82057) | 98.34th | v3 (v2023.03.01) |
| Mar 22, 2024 | 79.50% (0.79504) | 98.20th | v3 (v2023.03.01) |
| Mar 8, 2024 | 76.08% (0.76083) | 98.08th | v3 (v2023.03.01) |
| Feb 24, 2024 | 80.26% (0.80259) | 98.20th | v3 (v2023.03.01) |
| Feb 10, 2024 | 82.45% (0.82449) | 98.28th | v3 (v2023.03.01) |
| Jan 14, 2024 | 80.29% (0.80294) | 98.03th | v3 (v2023.03.01) |
| Dec 17, 2023 | 78.60% (0.78602) | 97.96th | v3 (v2023.03.01) |
| Dec 2, 2023 | 77.21% (0.77213) | 97.91th | v3 (v2023.03.01) |
| Nov 8, 2023 | 78.43% (0.78434) | 97.93th | v3 (v2023.03.01) |
| Nov 4, 2023 | 93.77% (0.93774) | 98.86th | v3 (v2023.03.01) |
| Oct 8, 2023 | 93.86% (0.93858) | 98.85th | v3 (v2023.03.01) |
| Sep 21, 2023 | 94.30% (0.94296) | 98.88th | v3 (v2023.03.01) |
| Sep 9, 2023 | 94.89% (0.94890) | 98.99th | v3 (v2023.03.01) |
| Aug 11, 2023 | 94.68% (0.94684) | 98.91th | v3 (v2023.03.01) |
| Jul 28, 2023 | 95.27% (0.95273) | 99.03th | v3 (v2023.03.01) |
| Jul 14, 2023 | 95.31% (0.95311) | 99.03th | v3 (v2023.03.01) |
| Jun 29, 2023 | 95.56% (0.95564) | 99.09th | v3 (v2023.03.01) |
| Jun 14, 2023 | 96.28% (0.96282) | 99.28th | v3 (v2023.03.01) |
| May 30, 2023 | 96.16% (0.96163) | 99.22th | v3 (v2023.03.01) |
| May 16, 2023 | 96.18% (0.96178) | 99.22th | v3 (v2023.03.01) |
| May 2, 2023 | 96.53% (0.96526) | 99.33th | v3 (v2023.03.01) |
| Apr 17, 2023 | 96.65% (0.96649) | 99.38th | v3 (v2023.03.01) |
| Apr 4, 2023 | 96.98% (0.96979) | 99.54th | v3 (v2023.03.01) |
| Mar 20, 2023 | 97.14% (0.97141) | 99.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.17% (0.97168) | 99.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 16.53% (0.16531) | 96.16th | v2 (v2022.01.01) |
| Apr 1, 2022 | 16.53% (0.16531) | 95.80th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.53% (0.16531) | 92.90th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.82% (0.07819) | 84.70th | v1 |
| Jan 6, 2022 | 7.82% (0.07819) | 84.53th | v1 |
| Oct 14, 2021 | 7.82% (0.07819) | 92.43th | v1 |
| Oct 1, 2021 | 1.85% (0.01855) | 75.77th | v1 |
| Sep 25, 2021 | 0.62% (0.00624) | 45.20th | v1 |
References (9)
- https://access.redhat.com/security/cve/CVE-2021-36749 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2007715 Issue Tracking
- https://github.com/advisories/GHSA-793h-6f7r-6qvm
- https://github.com/advisories/GHSA-9p5g-vg43-mj5r Advisory
- https://lists.apache.org/thread.html/r304dfe56a5dfe1b2d9166b24d2c74ad1c6730338b20aef77a00ed2be%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r304dfe56a5dfe1b2d9166b24d2c74ad1c6730338b20aef77a00ed2be@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rc9400a70d0ec5cdb8a3486fc5ddb0b5282961c0b63e764abfbcb9f5d%40%3Cdev.druid.apache.org%3E x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-36749
- https://www.cve.org/CVERecord?id=CVE-2021-36749
Change history (0)
No recorded changes yet.