Description
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
Remediation
References
https://lists.apache.org/thread/lh2kcl4j45q7xj4w6rqf6kwf0mvyp2o6
Related Vulnerabilities
CVE-2020-6831 Vulnerability in npm package electron
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel-traverse
CVE-2019-10434 Vulnerability in maven package com.mtvi.plateng.hudson:ldapemail
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2022-34781 Vulnerability in maven package com.xebialabs.ci:xlrelease-plugin