QID 980737
QID 980737: Java (maven) Security Update for org.apache.kylin:kylin-core-common (GHSA-gprm-xqrc-c2j3)
Kylin has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gprm-xqrc-c2j3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-gprm-xqrc-c2j3 -
github.com/advisories/GHSA-gprm-xqrc-c2j3
CVEs related to QID 980737
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gprm-xqrc-c2j3 | org.apache.kylin:kylin-core-common |
|