CVE-2021-25646
HIGH 9.0EPSS 99.0%
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 99.00% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-732
- Published
- 2021-01-29
- Updated
- 2025-02-13
Proof-of-concept exploits (15)
- http://packetstormsecurity.com/files/162345/Apache-Druid-0.20.0-Remote-Command-Execution.…
- Ormicron/CVE-2021-25646-GUI1★ · 2021-02-05
- ShadowLance2/Apache-Druid-CVE-2021-25646-Exploit0★ · 2025-07-06
- Vulnmachines/Apache-Druid-CVE-2021-256463★ · 2021-06-10
- W4nde3/toolkits0★ · 2022-04-15
- bealright/Poc-Exp2★ · 2022-01-30
- dnr6419/Druid_docker0★ · 2021-10-29
- givemefivw/CVE-2021-256463★ · 2021-04-15
- gps1949/CVE-2021-256460★ · 2025-03-12
- j2ekim/CVE-2021-256464★ · 2021-12-12
- k7pro/CVE-2021-25646-exp4★ · 2025-02-18
- lp008/CVE-2021-256462★ · 2021-02-03
- luobai8/CVE-2021-25646-exp4★ · 2025-02-18
- tiemio/RCE-PoC-CVE-2021-256461★ · 2025-05-09
- yaunsky/cve-2021-2564617★ · 2021-02-03
Nuclei templates (1)
Metasploit modules (1)
Vulhub environments (1)
Exploit collections (3)
- helloexp/0day/tree/master/96-Java%E4%B8%93%E5%8C%BA/24-Druid/CVE-2021-25646
- tzwlhack/Vulnerability/blob/main/Apache%20Druid%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-25646.yaml