Skip to main content

apache-druid-javascript-rce-vulnerability-analysis

Understanding the CVE in Apache Druid 0.20.0 where authenticated attackers can execute arbitrary code via JavaScript payloads. The vulnerability exploits @JacksonInject with empty key "" to override JavaScriptConfig and enable JavaScript execution even when disabled. Use this skill to understand the attack vector and plan the fix.

Zur Installation springen

Quellinformationen

Repository
cxcscmu/SkillLearnBench
Letzte Quellaktivität
24. April 2026 um 05:14
Erkannte Sprache von SKILL.md
Englisch
Sterne
77
Forks
4

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.