kylinGHSA-mr9j-4j48-xcm2
Apache Kylin Authentication Bypass Vulnerability
High7.5CVE-2025-61733 · Published Oct 2, 2025 · updated Feb 22, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | >= 4.0.0, < 5.0.3 | 5.0.3 |
Details and references
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-288
- Also known as
- CVE-2025-61733
- nvd.nist.gov/vuln/detail/CVE-2025-61733
- github.com/apache/kylin/pull/2336
- github.com/apache/kylin/commit/8b2cb8c71bd9885d70dad4f1a9822e38d9949b8c
- github.com/apache/kylin
- issues.apache.org/jira/browse/KYLIN-6081
- lists.apache.org/thread/8wmcffly6gp50nmfw8j4w3hlmv843yo0
- www.openwall.com/lists/oss-security/2025/09/30/7
More kylin advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 22025 | Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability CVE-2025-61735High7.3fixed in 5.0.3 | High7.3 | 5.0.3 |
| Oct 22025 | Apache Kylin Files or Directories Accessible to External Parties CVE-2025-61734High7.5fixed in 5.0.3 | High7.5 | 5.0.3 |
| Mar 272025 | Apache Kylin Code Injection via JDBC Configuration Alteration CVE-2025-30067Lowfixed in 5.0.2 | Low | 5.0.2 |
| Nov 42024 | Apache Kylin Session Fixation vulnerability CVE-2024-23590High9.1fixed in 5.0.0 | High9.1 | 5.0.0 |
| Dec 302022 | Apache Kylin vulnerable to Command injection by Useless configuration CVE-2022-43396High8.8fixed in 4.0.3 | High8.8 | 4.0.3 |
| Feb 102022 | Authentication bypass in Apache Kylin CVE-2020-13937Medium5.3fixed in 3.1.1, 4.0.0-beta | Medium5.3 | 3.1.1, 4.0.0-beta |