Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.apache.druid:druid-core | 0 |
| Apache Software Foundation | Apache Druid | Apache Druid |
| apache | druid | 0 |
Timeline
- Jul 2, 2021 CVE Published
- Jul 2, 2021 EPSS Score
- Jul 2, 2021 PoC Published
- Aug 30, 2021 EPSS Score
- Sep 24, 2021 EPSS Score
- Sep 24, 2021 PoC Published
- Oct 15, 2021 EPSS Score
- Oct 29, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 25, 2022 EPSS Score
- Jun 24, 2022 EPSS Score
- Oct 22, 2022 EPSS Score
References
- https://lists.apache.org/thread.html/r29e45561343cc5cf7d3290ee0b0e94e565faab19c20d022df9b5e29c%40%3Cdev.druid.apache.org%3E url
- [oss-security] 20210702 CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended mailing-list
- [announce] 20210701 CVE-2021-26920: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended mailing-list
- [druid-dev] 20210923 CVE-2021-36749: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) mailing-list
- [oss-security] 20210923 CVE-2021-36749: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) mailing-list
- [announce] 20210923 CVE-2021-36749: Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2021-26920 advisory
- https://lists.apache.org/thread.html/r304dfe56a5dfe1b2d9166b24d2c74ad1c6730338b20aef77a00ed2be@%3Cannounce.apache.org%3E url
- https://lists.apache.org/thread.html/r61aab724cf97d80da7f02d50e9af6de5c7c40dd92dab7518746fbaa2@%3Cannounce.apache.org%3E url
- https://lists.apache.org/thread.html/rc9400a70d0ec5cdb8a3486fc5ddb0b5282961c0b63e764abfbcb9f5d@%3Cdev.druid.apache.org%3E url