CVE-2021-36749 describes an improper authorization vulnerability in Apache Druid's ingestion system. The HTTP InputSource component allows authenticated users to specify arbitrary URLs for data ingestion. Due to insufficient validation, users can supply file URLs to the HTTP InputSource, enabling them to read files from the local file system with the privileges of the Druid server process. This bypasses application-level restrictions that may only expose the HTTP InputSource and not the Local InputSource, allowing users to access unintended data sources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2021-36749, an arbitrary file read vulnerability in Apache Druid versions 0.21.1 and below. The main file, CVE-2021-36749.py, is a Python script that sends a crafted POST request to the Druid indexer API endpoint '/druid/indexer/v1/sampler?for=connect'. The payload abuses the API's firehose configuration to read arbitrary files from the server, demonstrated by attempting to read '/etc/passwd'. The script checks for the presence of 'root:x:0' in the response to confirm exploitation. The README provides usage instructions, including a curl command for manual exploitation. The exploit requires network access to the vulnerable Druid instance and does not require authentication if the API is exposed. The repository is structured simply, with one exploit script and a README, and is focused solely on demonstrating the vulnerability.
This repository is a collection of Python-based exploit and POC scripts targeting a variety of web applications, firewalls, and network devices. The scripts are organized by target product and vulnerability, with each directory containing one or more scripts for a specific exploit. The main capabilities include: - Arbitrary file read exploits (e.g., Apache Druid CVE-2021-36749, Apache Solr <=8.8.1, Landray OA, Kyan, etc.) - Remote command execution (RCE) exploits (e.g., Confluence CVE-2021-26084, TamronOS-IPTV, ZeroShell CVE-2019-12725, phpStudy backdoor, etc.) - Arbitrary file upload (ShowDoc CNVD-2020-26585) - Credential extraction and information disclosure (Wayos firewall, Ruijie EG Gateway, Kyan, Landray OA) - Unauthorized admin access (YCXF admin system) Each script typically supports both single-target and batch scanning modes, with options for verification and exploitation. The scripts use HTTP(S) requests to interact with vulnerable endpoints, often leveraging unauthenticated or weakly authenticated interfaces. The payloads include file read requests, command injection, and webshell uploads. The repository is operational in maturity, providing working exploits and not just detection scripts. All scripts are written in Python and are intended for use in authorized security testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.