kylinGHSA-752q-72qc-rc66
Apache Kylin Session Fixation vulnerability
High9.1CVE-2024-23590 · Published Nov 4, 2024 · updated Jul 11, 2025
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | >= 2.0.0, < 5.0.0 | 5.0.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-384
- Also known as
- CVE-2024-23590
More kylin advisories
All kylin| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 22025 | Apache Kylin Files or Directories Accessible to External Parties | High7.5 | 5.0.3 |
| Oct 22025 | Apache Kylin Authentication Bypass Vulnerability | High7.5 | 5.0.3 |
| Oct 22025 | Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability | High7.3 | 5.0.3 |
| Mar 272025 | Apache Kylin Code Injection via JDBC Configuration Alteration | Low | 5.0.2 |
| Dec 302022 | Apache Kylin vulnerable to Command injection by Useless configuration | High8.8 | 4.0.3 |
| Feb 102022 | Authentication bypass in Apache Kylin | Medium5.3 | 3.1.1+1 more |