Skip to content
kylinGHSA-q656-g2x3-8cgh

Kylin can receive user input and load any class through Class.forName(...)

MediumCVE-2021-31522 · Published Jan 8, 2022 · updated Dec 4, 2024

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
< 3.1.33.1.3
>= 4.0.0, < 4.0.14.0.1
Details and references

More kylin advisories

All kylin
Advisory
Authentication bypass in Apache Kylin
Medium5.3Feb 10, 2022
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin
High7.5Jan 8, 2022
Use of Hard-coded Credentials in Apache Kylin
High7.5Jan 8, 2022
SQL Injection in Apache Kylin
Medium6.5Jan 8, 2022
Server-Side Request Forgery in Apache Kylin
MediumJan 8, 2022
Command Injection in Apache Kylin
MediumJan 8, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.