QID 980738
QID 980738: Java (maven) Security Update for org.apache.kylin:kylin-server-base (GHSA-hx5g-8hq2-8x4w)
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hx5g-8hq2-8x4w for updates pertaining to this vulnerability.
Vendor References
- GHSA-hx5g-8hq2-8x4w -
github.com/advisories/GHSA-hx5g-8hq2-8x4w
CVEs related to QID 980738
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hx5g-8hq2-8x4w | org.apache.kylin:kylin-server-base |
|