kylinGHSA-f5q9-j9r2-34gq
Apache Kylin vulnerable to Command injection by Useless configuration
High8.8CVE-2022-43396 · Published Dec 30, 2022 · updated Apr 11, 2025
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the `kylin.engine.spark-cmd` parameter of `conf`.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | >= 2.0.0, < 4.0.3 | 4.0.3 |
Details and references
More kylin advisories
All kylin| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102022 | Authentication bypass in Apache Kylin | Medium5.3 | 3.1.1+1 more |
| Jan 82022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin | High7.5 | 3.1.3+1 more |
| Jan 82022 | Use of Hard-coded Credentials in Apache Kylin | High7.5 | 3.1.3+1 more |
| Jan 82022 | SQL Injection in Apache Kylin | Medium6.5 | 3.1.3 |
| Jan 82022 | Server-Side Request Forgery in Apache Kylin | Medium | 3.1.3 |
| Jan 82022 | Kylin can receive user input and load any class through Class.forName(...) | Medium | 3.1.3+1 more |