An OWASP Dependency-Check review found 25 outdated Apache Drill 1.16.0 dependencies with known vulnerabilities after false positives were excluded. The reported exposures included jackson-databind 2.9.5, affected by critical CVE-2018-14721 (CVSS 10.0), and Derby 10.10.2.0, affected by CVE-2015-1832 (CVSS 9.1), alongside issues involving Kafka, Kudu/protobuf, and other libraries. The findings identify vulnerable component versions but do not establish exploitability, active exploitation, or compromise of Drill deployments.
Apache created DRILL-7416 to coordinate upgrades, replacements, and releases needed to remediate the dependencies. Proposed actions included updating direct third-party libraries and Drill-shaded components; some fixes required upstream or release-level work for shaded Guava, jQuery, Bootstrap, and Kudu's Netty dependency. Updating kudu-client to 1.10.0 was identified as only a partial mitigation because the associated Netty dependency would remain affected by CVE-2019-16869.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Bradley Parker created DRILL-7416 for Apache Drill 1.16.0 after a review identified 25 dependencies requiring updates after false positives were excluded. The issue proposed upgrades or replacements for affected components, while noting that some fixes required new Drill releases or an upstream Netty update for Kudu.
Bradley Parker of IBM's product-security team reported that an OWASP Dependency-Check scan found 24 Apache Drill dependencies with known CVEs, including Jackson Databind 2.9.5 and Derby 10.10.2.0. Apache Drill committer Charles Givre asked him to open a JIRA issue to begin discussion of the findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
lists.apache.org
Open sourcelists.apache.org
Open sourceissues.apache.org
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.