← Vulnerability feed

Vulnerability record · CVE-2024-45384 · published 17 September 2024

CVE-2024-45384: Apache druid error message information leak vulnerability

Apache · Druid

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability. While we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.

5.3 CVSS 3.1 Medium EPSS 0.82% · top 44.4% CWE-209 · Error message information leak
5.3CVSS 3.1 base score
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability. While we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-23906Apache druid improper authentication vulnerabilityAffected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-…EPSS 1.1%9.8CVE-2025-59390Apache druid vulnerabilityApache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…EPSS 0.61%8.8CVE-2021-26919Apache druid vulnerabilityApache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio…EPSS 23%8.8CVE-2021-25646Apache Druid JavaScript execution bypass enables remote code executionApache Druid supports executing user-provided JavaScript embedded in requests, a feature intended for high-trust environments and disabled by default…EPSS 99%analysed6.5CVE-2024-45537Apache druid improper input validation vulnerabilityApache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…EPSS 0.63%6.5CVE-2021-36749Apache Druid HTTP InputSource authorization bypass allows local file readApache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file…EPSS 81%analysed6.5CVE-2021-26920Apache druid vulnerabilityIn the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…EPSS 9.5%6.5CVE-2020-1958Apache druid injection vulnerabilityWhen LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…EPSS 4.6%

Source: NIST National Vulnerability Database (record CVE-2024-45384), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.