← Vulnerability feed

Vulnerability record · CVE-2025-27888 · published 20 March 2025

CVE-2025-27888: Apache druid cross-site scripting vulnerability

Apache · Druid

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected. Users are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.

5.8 CVSS 4.0 Medium EPSS 1.8% · top 23.0% CWE-79 · Cross-site scriptingCWE-601 · Open redirect
5.8CVSS 4.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected. Users are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://lists.apache.org/thread/c0qo989pwtrqkjv6xfr0c30dnjq8vf39 Issue TrackingMailing ListVendor Advisory
http://www.openwall.com/lists/oss-security/2025/03/19/7 Mailing ListThird Party Advisory

Track CVE-2025-27888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-23906Apache druid improper authentication vulnerabilityAffected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-…EPSS 1.1%9.8CVE-2025-59390Apache druid vulnerabilityApache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…EPSS 0.61%8.8CVE-2021-26919Apache druid vulnerabilityApache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio…EPSS 23%8.8CVE-2021-25646Apache Druid JavaScript execution bypass enables remote code executionApache Druid supports executing user-provided JavaScript embedded in requests, a feature intended for high-trust environments and disabled by default…EPSS 99%analysed6.5CVE-2024-45537Apache druid improper input validation vulnerabilityApache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…EPSS 0.63%6.5CVE-2021-36749Apache Druid HTTP InputSource authorization bypass allows local file readApache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file…EPSS 81%analysed6.5CVE-2021-26920Apache druid vulnerabilityIn the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…EPSS 9.5%6.5CVE-2020-1958Apache druid injection vulnerabilityWhen LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…EPSS 4.6%

Source: NIST National Vulnerability Database (record CVE-2025-27888), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.