Security Flaw in Apache Calcite Affects Druid and Splunk Connectivity
CVE-2020-13955
What is CVE-2020-13955?
A vulnerability exists in the HttpUtils#getURLConnection method of Apache Calcite, which disables hostname verification for HTTPS connections. This flaw exposes clients to man-in-the-middle attacks, compromising data security during interactions with Druid and Splunk through their relevant Calcite adapters. As a result, sensitive information may be leaked. From version 1.26 onward, Apache Calcite addresses this issue by enabling hostname verification using the default JVM truststore, thus enhancing connection security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Calcite Apache Calcite 0.8 to 1.25
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved