SCA: security update for org.apache.druid:druid (GHSA-2xcr-p767-f3rv)

medium Tenable Self-Hosted Container Security Plugin ID 421198

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input
During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect')
vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid
management proxy, a request that has a specially crafted URL could be used to redirect the request to an
arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated
for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled
to mitigate this vulnerability. If the management proxy is disabled, some web console features will not
work properly, but core functionality is unaffected. Users are recommended to upgrade to Druid 31.0.2 or
Druid 32.0.1, which fixes the issue. (CVE-2025-27888)

See Also

https://github.com/advisories/GHSA-2xcr-p767-f3rv

Plugin Details

Severity: Medium

ID: 421198

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 3/22/2025

Updated: 6/1/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.42

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2025-27888

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.8

Threat Score: 1.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/20/2025

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2025-27888