org.apache.kylin:kylin-server-base
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.kylin:kylin-server-basepage 1 of 1
- CVE-2020-13925CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.1.02020-07-14
vulnerable: 1.5.3 ... 3.0.2 (27 versions)
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have th…
- CVE-2020-13926CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.1.02020-07-14
vulnerable: 1.5.3 ... 3.0.2 (27 versions)
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection at…
- CVE-2020-1937HIGHCVSS 8.8EG 8.8✓ Fixed in 3.0.12020-02-24
vulnerable: 3.0.0
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
- CVE-2022-24697CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.0.22022-10-13
vulnerable: 1.5.3 ... 4.0.1 (35 versions)
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- …
- CVE-2022-44621CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.0.32022-12-30
vulnerable: 2.0.0 ... 4.0.2 (32 versions)
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Check whether org.apache.kylin:kylin-server-base is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.kylin:kylin-server-base CVEs against the assets you own.
Start Free Scan →