kylinGHSA-q656-g2x3-8cgh
Kylin can receive user input and load any class through Class.forName(...)
MediumCVE-2021-31522 · Published Jan 8, 2022 · updated Dec 4, 2024
Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | < 3.1.3 | 3.1.3 |
| >= 4.0.0, < 4.0.1 | 4.0.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-470
- Also known as
- CVE-2021-31522
More kylin advisories
All kylin| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102022 | Authentication bypass in Apache Kylin | Medium5.3 | 3.1.1+1 more |
| Jan 82022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin | High7.5 | 3.1.3+1 more |
| Jan 82022 | Use of Hard-coded Credentials in Apache Kylin | High7.5 | 3.1.3+1 more |
| Jan 82022 | SQL Injection in Apache Kylin | Medium6.5 | 3.1.3 |
| Jan 82022 | Server-Side Request Forgery in Apache Kylin | Medium | 3.1.3 |
| Jan 82022 | Command Injection in Apache Kylin | Medium | 4.0.1 |