CVE-2025-27888

Published Mar 20, 2025

Last updated 9 months ago

CVSS medium 5.8
Apache Druid
Splunk

Overview

Description
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected. Users are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed
Products
druid

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
5.4
Impact score
2.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-79

Social media

Hype score
Not currently trending
  1. XBOW found a new zero-day in Apache Druid. It wasn't just a lucky guess. XBOW is trained to think like a human attacker, using historical CVE knowledge to find a novel SSRF (CVE-2025-27888). This is how AI-powered pentesting turns old knowledge into new findings. Read the https

    @Xbow

    23 Sept 2025

    9099 Impressions

    15 Retweets

    114 Likes

    55 Bookmarks

    3 Replies

    4 Quotes

  2. XBOW found a new zero-day in Apache Druid. It wasn't just a lucky guess. XBOW is trained to think like a human attacker, using historical CVE knowledge to find a novel SSRF (CVE-2025-27888). This is how AI-powered pentesting turns old knowledge into new findings. Read the https

    @Xbow

    23 Sept 2025

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2025-27888 - high 🚨 Apache Druid - Server-Side Request Forgery > Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page ... 👾 https://t.co/9WnfmkB3TW @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    18 Aug 2025

    298 Impressions

    2 Retweets

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-27888: Apache Druid Flaw Opens Door to SSRF and XSS Risks in Real-Time Analytics Platforms https://t.co/TRwDiEcafR

    @Dinosn

    23 Mar 2025

    4805 Impressions

    32 Retweets

    91 Likes

    23 Bookmarks

    2 Replies

    0 Quotes

  5. Apacheは、Apache Druidに深刻な脆弱性(CVE-2025-27888)を公開。SSRF、XSS、オープンリダイレクトの複合型で、管理プロキシ経由で悪意あるリダイレクトが可能に。認証済みの攻撃者が被害者をフィッシング等に誘導する恐れがある。 https://t.co/2wSCTcGY5g

    @yousukezan

    23 Mar 2025

    1227 Impressions

    0 Retweets

    12 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-27888 Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redi… https://t.co/tx1tI4iWtq

    @CVEnew

    20 Mar 2025

    414 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations