KEVIntel
8.8
CVSS
High

CVE-2021-25646

PUBLISHED

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Apache Software Foundation
Product
Apache Druid
Published
Jan 29, 2021
EPSS

Description

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

apache java nuclei_scanner metasploit

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 9.0

AV:N/AC:L/Au:S/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2025-04-27 00:00:00 UTC · Source

Proof of concept available

Recorded 2021-12-12 14:40:12 UTC · Source

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 28, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

apache_druid_js_rce

metasploit · Created Unknown

Metasploit module for CVE-2021-25646

k7pro/CVE-2021-25646-exp

github · Created 2024-10-04 15:06:37 UTC · 4 stars

CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具

j2ekim/CVE-2021-25646

github · Created 2021-12-12 14:40:12 UTC · 4 stars

Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646

givemefivw/CVE-2021-25646

github · Created 2021-04-14 15:36:04 UTC · 3 stars

CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本

Vulnmachines/Apache-Druid-CVE-2021-25646

github · Created 2021-02-13 11:48:35 UTC · 3 stars

lp008/CVE-2021-25646

github · Created 2021-02-03 06:45:54 UTC · 2 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel

  • Detected by Metasploit