Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 07 Jul 2022 13:38:43 +0000
From: Abhishek Agarwal <>
Subject: CVE-2021-44791: Apache Druid: Reflected XSS on certain HTTP

Severity: low


In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.


Upgrade to Druid 0.23.0 or later.


This issue was discovered by DangKhai from Viettel Cyber Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.