Rewterz
Rewterz Threat Alert – Nanocore – IoCs
March 29, 2021
Rewterz
Rewterz Threat Advisory – Multiple Netgear ProSAFE Vulnerabilities
March 30, 2021

Rewterz Threat Advisory – CVE-2021-26919 – Apache Druid code execution

Severity

High

Analysis Summary

Apache Druid could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a flaw in the JDBC function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code from a malicious MySQL server within Druid server processes.

Impact

Gain access

Affected Vendors

Apache

Affected Products

Apache Druid 0.20.1

Remediation

Upgrade to the latest version of Druid (0.20.2 or later).

Apache Web site