Vulnerability record · CVE-2021-36749 · published 24 September 2021
CVE-2021-36749: Apache Druid HTTP InputSource authorization bypass allows local file read
Apache · Druid
Apache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file system, with the privileges of the Druid server process. It matters most when Druid sits behind an application that permits the HTTP InputSource but blocks the Local InputSource, because the application-level restriction can be bypassed. The fix claimed for 0.21.0 under CVE-2021-26920 was not actually present in 0.21.0 or 0.21.1.
Description
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource. This issue was previously mentioned as being fixed in 0.21.0 as per CVE-2021-26920 but was not fixed in 0.21.0 or 0.21.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw gives authenticated local file read with high confidentiality impact and a very high EPSS score, though it requires valid credentials and is not known to be exploited in the wild.
What it is
Apache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file system, with the privileges of the Druid server process. It matters most when Druid sits behind an application that permits the HTTP InputSource but blocks the Local InputSource, because the application-level restriction can be bypassed. The fix claimed for 0.21.0 under CVE-2021-26920 was not actually present in 0.21.0 or 0.21.1.
Impact
An attacker with a Druid account gains read access to files reachable by the Druid server process, exposing configuration, credentials or other sensitive local data. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.
Attack surface
Reached over the network through the Druid ingestion interface by an authenticated user; no user interaction is required. The flaw is an incorrect authorization check (CWE-863) on the HTTP InputSource, and the practical risk is highest where Druid is accessed indirectly through a front-end application.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.809 (99.6th percentile), indicating substantial predicted exploitation activity. References are vendor advisories and mailing list posts only, with no public exploit tag.
What to do
- Upgrade Apache Druid past the affected 0.21.0 and 0.21.1 releases to a version where the HTTP InputSource restriction is actually enforced.
- If upgrade is not immediate, restrict or disable the HTTP InputSource for untrusted users and block ingestion configurations that accept arbitrary file URLs.
- Ensure Druid is never exposed directly to untrusted networks and that front-end applications cannot pass user-controlled URLs into the HTTP InputSource.
- Run the Druid server process with a least-privilege account and limit its read access to sensitive local files and directories.
- Audit Druid accounts and ingestion permissions, removing or narrowing access for users who do not need to define input sources.
Detection
- Monitor Druid ingestion requests and task logs for HTTP InputSource configurations containing file:// or other local path URLs.
- Alert on Druid server process reads of sensitive files such as /etc/passwd, configuration files or credential stores.
- Review Druid audit and access logs for ingestion task creation by accounts that normally do not submit ingestion jobs.
- Correlate outbound or local file access by the Druid process with ingestion task activity to spot unauthorized data reads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-36749 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36749), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.