Skip to content
kylinGHSA-p86w-w5rh-m3hx

Apache Kylin Files or Directories Accessible to External Parties

High7.5CVE-2025-61734 · Published Oct 2, 2025 · updated Nov 5, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
>= 4.0.0, < 5.0.35.0.3
Details and references

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-552
Also known as
CVE-2025-61734

More kylin advisories

All
DateAdvisory
Oct 22025Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61735High7.3fixed in 5.0.3
Oct 22025Apache Kylin Authentication Bypass Vulnerability
CVE-2025-61733High7.5fixed in 5.0.3
Mar 272025Apache Kylin Code Injection via JDBC Configuration Alteration
CVE-2025-30067Lowfixed in 5.0.2
Nov 42024Apache Kylin Session Fixation vulnerability
CVE-2024-23590High9.1fixed in 5.0.0
Dec 302022Apache Kylin vulnerable to Command injection by Useless configuration
CVE-2022-43396High8.8fixed in 4.0.3
Feb 102022Authentication bypass in Apache Kylin
CVE-2020-13937Medium5.3fixed in 3.1.1, 4.0.0-beta

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.