kylinGHSA-mgpf-hhgf-cxg4
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin
High7.5CVE-2021-45457 · Published Jan 8, 2022 · updated Nov 8, 2023
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | < 3.1.3 | 3.1.3 |
| >= 4.0.0, < 4.0.1 | 4.0.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-522
- Also known as
- CVE-2021-45457
More kylin advisories
All kylin| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102022 | Authentication bypass in Apache Kylin | Medium5.3 | 3.1.1+1 more |
| Jan 82022 | Use of Hard-coded Credentials in Apache Kylin | High7.5 | 3.1.3+1 more |
| Jan 82022 | SQL Injection in Apache Kylin | Medium6.5 | 3.1.3 |
| Jan 82022 | Server-Side Request Forgery in Apache Kylin | Medium | 3.1.3 |
| Jan 82022 | Kylin can receive user input and load any class through Class.forName(...) | Medium | 3.1.3+1 more |
| Jan 82022 | Command Injection in Apache Kylin | Medium | 4.0.1 |