CVE-2024-45384
MEDIUM EPSS 52.6%
Published Sep 17, 20241y ago · Modified Jun 17, 20261w ago
5.3 CVSS 3.1
Published Sep 17, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability. While we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
52.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-209
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| apache | druid | * | ≥0.18.0 – <30.0.1 |
References 2
- openwall.com http://www.openwall.com/lists/oss-security/2024/09/17/1
- lists.apache.org https://lists.apache.org/thread/gr94fnp574plb50lsp8jw4smvgv1lbz1
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.