Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31118
HistoryJul 05, 2021 - 3:36 a.m.

Information Disclosure

2021-07-0503:36:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
druid-core
information disclosure
http inputsource

EPSS

0.002

Percentile

51.9%

druid-core is vulnerable to information disclosure. An attacker is able bypass the application-level restriction and read data from other sources than intended by passing a file URL to the HTTP InputSource.

EPSS

0.002

Percentile

51.9%