CVE-2024-45384
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2024
Last modified:
14/03/2025
Description
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.<br />
This could allow an attacker to manipulate a pac4j session cookie.<br />
<br />
This issue affects Apache Druid versions 0.18.0 through 30.0.0.<br />
Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.<br />
<br />
While we are not aware of a way to meaningfully exploit this flaw, we <br />
nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue<br />
and ensuring you have a strong <br />
druid.auth.pac4j.cookiePassphrase as a precaution.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:* | 0.18.0 (including) | 30.0.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



