CVE-2024-45384

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2024
Last modified:
14/03/2025

Description

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.<br /> This could allow an attacker to manipulate a pac4j session cookie.<br /> <br /> This issue affects Apache Druid versions 0.18.0 through 30.0.0.<br /> Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.<br /> <br /> While we are not aware of a way to meaningfully exploit this flaw, we <br /> nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue<br /> and ensuring you have a strong <br /> druid.auth.pac4j.cookiePassphrase as a precaution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:* 0.18.0 (including) 30.0.1 (excluding)