Reflected XSS on certain HTTP endpoints
Description
Apache Druid versions 0.22.1 and earlier are vulnerable to reflected XSS via specially-crafted links that return unescaped URL parameters in HTML responses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Apache Druid versions 0.22.1 and earlier are vulnerable to reflected XSS via specially-crafted links that return unescaped URL parameters in HTML responses.
Vulnerability
Overview
CVE-2021-44791 is a reflected cross-site scripting (XSS) vulnerability in Apache Druid, a high-performance real-time analytics database. The flaw exists in versions 0.22.1 and earlier, where certain specially-crafted links cause unescaped URL parameters to be reflected back in HTML responses. This lack of proper output encoding allows an attacker to inject arbitrary JavaScript into the response page [1][2].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL containing JavaScript payloads in query parameters. When a victim clicks on such a link, the unescaped parameters are included in the HTML response from the Druid server, causing the browser to execute the injected script. No authentication is required to trigger the reflection, but the victim must be logged into the Druid console for the attack to have full effect [2].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking, data theft, or unauthorized actions performed on behalf of the victim within the Druid web console. The vulnerability is classified as medium severity (CVSS 6.1) due to the requirement for user interaction [2].
Mitigation
Apache has addressed this issue in Druid version 0.22.2 and later. Users are strongly advised to upgrade to the latest release. As a workaround, administrators can restrict access to the Druid web console or implement web application firewall rules to filter malicious query parameters. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date [2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.druid:druidMaven | < 0.23.0 | 0.23.0 |
Affected products
2- Apache Software Foundation/Apache Druidv5Range: Apache Druid
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-8rmv-98m4-g5c6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-44791ghsaADVISORY
- lists.apache.org/thread/lh2kcl4j45q7xj4w6rqf6kwf0mvyp2o6ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.