Loading HuntDB...

GHSA-ppxx-m926-g569

GitHub Security Advisory

Apache Kylin vulnerable to remote code execution

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

Affected Packages

Maven org.apache.kylin:kylin-core-common
Affected versions: 0 (fixed in 4.0.2)
Maven org.apache.kylin:kylin-spark-project
Affected versions: 0 (fixed in 4.0.2)
Maven org.apache.kylin:kylin-server-base
Affected versions: 0 (fixed in 4.0.2)

Related CVEs

Key Information

GHSA ID
GHSA-ppxx-m926-g569
Published
July 6, 2023 7:24 PM
Last Modified
May 16, 2025 10:12 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.kylin:kylin-core-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.