GHSA-ppxx-m926-g569
GitHub Security Advisory
Apache Kylin vulnerable to remote code execution
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.
Affected Packages
Maven
org.apache.kylin:kylin-core-common
Affected versions:
0
(fixed in 4.0.2)
Maven
org.apache.kylin:kylin-spark-project
Affected versions:
0
(fixed in 4.0.2)
Maven
org.apache.kylin:kylin-server-base
Affected versions:
0
(fixed in 4.0.2)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.