Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
https://www.darkreading.com/cloud-security/lucifer-botnet-heat-apache-hadoop-servers
https://www.aquasec.com/blog/lucifer-ddos-botnet-malware-is-targeting-apache-big-data-stack/
https://github.com/shahdawadfallah-sys/Cybersecurity-Capstone-Project
https://github.com/DavidEspin141/TFG-Pentesting-IA
https://github.com/ShadowLance2/Apache-Druid-CVE-2021-25646-Exploit
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/gps1949/CVE-2021-25646
https://github.com/minchan02/CVE-Manage
https://github.com/luobai8/CVE-2021-25646-exp
https://github.com/j2ekim/CVE-2021-25646
https://securitylab.github.com/research/rhino-in-the-room/
https://github.com/givemefivw/CVE-2021-25646
https://github.com/Yang0615777/PocList
https://github.com/1n7erface/PocList
https://github.com/Ormicron/CVE-2021-25646-GUI
https://github.com/AirEvan/CVE-2021-25646-GUI
http://packetstormsecurity.com/files/162345/Apache-Druid-0.20.0-Remote-Command-Execution.html