apache druid CVE-2020-1958 is a vulnerability in Apache Druid
Published on April 1, 2020

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.

NVD


Products Associated with CVE-2020-1958

Want to know whenever a new CVE is published for Apache Druid? stack.watch will email you.

 

Affected Versions

Apache Druid Version 0.17.0 is affected by CVE-2020-1958

Exploit Probability

EPSS
15.57%
Percentile
94.57%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.