Executive brief
Apache Druid: Users can provide MySQL JDBC properties not on allow list
Affected products
- Maven org.apache.druid:druid
Junglewise Threat Intelligence
CVE-2024-45537 · Severity: low · CVSS 3.1 · Published 2024-09-17
Technologies: org.apache.druid:druid (Maven). Vendors: Maven.
Apache Druid: Users can provide MySQL JDBC properties not on allow list