Baseweb JSite Apache Druid Monitoring Console Access Control Vulnerability

Vulnerability

A critical access control vulnerability has been identified in Baseweb JSite version 1.0, specifically within the Apache Druid Monitoring Console. The issue arises in the file '/druid/index.html', where improper access controls allow unauthorized users to access sensitive interfaces without authentication. This vulnerability can be exploited remotely, potentially leading to unauthorized access to confidential information.

Impact

Exploitation of this vulnerability allows for unauthorized access to the Apache Druid Monitoring Console, where sensitive information can be accessed without authentication.

Reproduction

To reproduce this vulnerability, access the '/druid/index.html' path on a JSite 1.0 installation. No authentication is required, and the vulnerability can be exploited remotely.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.