Known vulnerabilities in Apache Foundation Apache Druid

Website: https://www.apache.org
Total Security Bulletins: 9

Security bulletins (9)

Secuity bulletin Severity Status Published
SB2025112807: Authentication bypass in Apache Druid Kerberos authenticator High
Patched
28.11.2025
SB2025032718: SSRF in Apache Druid High
Patched
27.03.2025
SB2022070725: Reflected XSS in Apache Druid Medium
Patched
07.07.2022
SB2021121615: Remote code execution in Apache Druid (Apache Log4j component) Critical
Patched Exploited
16.12.2021
SB2021092404: Security restrictions bypass in Apache Druid Low
Patched Public exploit
24.09.2021
SB2021070509: Security restrictions bypass in Apache Druid Low
Patched
05.07.2021
SB2021033019: Remote code execution in Apache Druid Medium
Patched
30.03.2021
SB2021020112: Remote code execution in Apache Druid Medium
Patched Public exploit
01.02.2021
SB2020040405: LDAP injection in Apache Druid Medium
Patched Public exploit
04.04.2020