Threat Encyclopedia
Apache.Druid.Loaddata.Arbitrary.File.Read
Description
This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Apache Druid.
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted request. A remote attacker may be able exploit this to disclose arbitrary files within the context of the application, via a crafted request.
Affected Products
Apache Druid prior to 0.22
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor:
https://druid.apache.org/