Skip to content
kylinGHSA-29m8-wh9p-5wc4

Apache Kylin Code Injection via JDBC Configuration Alteration

LowCVE-2025-30067 · Published Mar 27, 2025

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.1. Users are recommended to upgrade to version 5.0.2 or above, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
>= 4.0.0, < 5.0.25.0.2
Details and references

More kylin advisories

All kylin
Advisory
Apache Kylin Files or Directories Accessible to External Parties
High7.5Oct 2, 2025
Apache Kylin Authentication Bypass Vulnerability
High7.5Oct 2, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High7.3Oct 2, 2025
Apache Kylin Session Fixation vulnerability
High9.1Nov 4, 2024
Apache Kylin vulnerable to Command injection by Useless configuration
High8.8Dec 30, 2022
Authentication bypass in Apache Kylin
Medium5.3Feb 10, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.