Headline
GHSA-8rmv-98m4-g5c6: Cross site scripting in Apache Druid
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
Cross site scripting in Apache Druid
Moderate severity GitHub Reviewed Published Jul 8, 2022 • Updated Jul 8, 2022
Related news
CVE-2021-44791
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.