Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.druid.extensions/druid-pac4j
  4. ›
  5. CVE-2024-45384

CVE-2024-45384: druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability

September 17, 2024 (updated March 14, 2025)

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie.

This issue affects Apache Druid versions 0.18.0 through 30.0.0. Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this vulnerability.

While we are not aware of a way to meaningfully exploit this flaw, we nevertheless recommend upgrading to version 30.0.1 or higher which fixes the issue and ensuring you have a strong druid.auth.pac4j.cookiePassphrase as a precaution.

References

  • github.com/advisories/GHSA-p72w-r6fv-6g5h
  • github.com/apache/druid
  • github.com/apache/druid/commit/74cab7a76c99da457c3a883939cc0b03301b8771
  • github.com/apache/druid/releases/tag/druid-30.0.1
  • lists.apache.org/thread/gr94fnp574plb50lsp8jw4smvgv1lbz1
  • nvd.nist.gov/vuln/detail/CVE-2024-45384

Code Behaviors & Features

Detect and mitigate CVE-2024-45384 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.18.0 before 30.0.1

Fixed versions

  • 30.0.1

Solution

Upgrade to version 30.0.1 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-209: Generation of Error Message Containing Sensitive Information
  • CWE-347: Improper Verification of Cryptographic Signature

Source file

maven/org.apache.druid.extensions/druid-pac4j/CVE-2024-45384.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:27 +0000.