QID 980737

QID 980737: Java (maven) Security Update for org.apache.kylin:kylin-core-common (GHSA-gprm-xqrc-c2j3)

Kylin has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to refer to GHSA-gprm-xqrc-c2j3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980737

    Software Advisories
    Advisory ID Software Component Link
    GHSA-gprm-xqrc-c2j3 org.apache.kylin:kylin-core-common URL Logo github.com/advisories/GHSA-gprm-xqrc-c2j3