Skip to content
kylinGHSA-5429-pjww-7675

SQL Injection in Apache Kylin

Medium6.5CVE-2021-36774 · Published Jan 8, 2022 · updated Feb 16, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
< 3.1.33.1.3
Details and references

Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Kylin server processes. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-668, CWE-89
Also known as
CVE-2021-36774

More kylin advisories

All
DateAdvisory
Jan 82022Command Injection in Apache Kylin
CVE-2021-45456Mediumfixed in 4.0.1
Jan 82022Kylin can receive user input and load any class through Class.forName(...).
CVE-2021-31522Mediumfixed in 3.1.3, 4.0.1
Jan 82022Server-Side Request Forgery in Apache Kylin
CVE-2021-27738Mediumfixed in 3.1.3
Jan 82022Use of Hard-coded Credentials in Apache Kylin
CVE-2021-45458High7.5fixed in 3.1.3, 4.0.1
Jan 82022In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin.
CVE-2021-45457High7.5fixed in 3.1.3, 4.0.1
Feb 102022Authentication bypass in Apache Kylin
CVE-2020-13937Medium5.3fixed in 3.1.1, 4.0.0-beta

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.