Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29866
HistoryMar 31, 2021 - 2:58 a.m.

Remote Code Execution

2021-03-3102:58:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
apache druid
remote code execution
mysql jdbc driver
arbitrary code
hacker-controlled server
malicious mysql server

EPSS

0.012

Percentile

85.5%

Apache Druid is vulnerable to remote code execution. Certain properties supported by the MySQL JDBC driver allows an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Druid server processes.

References

EPSS

0.012

Percentile

85.5%