Skip to content
kylinGHSA-752q-72qc-rc66

Apache Kylin Session Fixation vulnerability

High9.1CVE-2024-23590 · Published Nov 4, 2024 · updated Jul 11, 2025

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
>= 2.0.0, < 5.0.05.0.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-384
Also known as
CVE-2024-23590

More kylin advisories

All kylin
Advisory
Apache Kylin Files or Directories Accessible to External Parties
High7.5Oct 2, 2025
Apache Kylin Authentication Bypass Vulnerability
High7.5Oct 2, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High7.3Oct 2, 2025
Apache Kylin Code Injection via JDBC Configuration Alteration
LowMar 27, 2025
Apache Kylin vulnerable to Command injection by Useless configuration
High8.8Dec 30, 2022
Authentication bypass in Apache Kylin
Medium5.3Feb 10, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.