Known Vulnerabilities for Kylin by Apache
Listed below are 9 of the newest known vulnerabilities associated with "Kylin" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24697 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration ... | 9.8 - CRITICAL | 2022-10-13 | 2023-08-08 |
| CVE-2021-36774 | Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain propert... | 6.5 - MEDIUM | 2022-01-06 | 2023-08-08 |
| CVE-2021-31522 | Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 a... | 9.8 - CRITICAL | 2022-01-06 | 2022-01-12 |
| CVE-2021-27738 | All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoint... | 7.5 - HIGH | 2022-01-06 | 2022-01-13 |
| CVE-2020-13937 | Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, ... | 5.3 - MEDIUM | 2020-10-19 | 2020-10-29 |
| CVE-2020-13926 | Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from s... | 9.8 - CRITICAL | 2020-07-14 | 2023-11-07 |
| CVE-2020-13925 | Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes... | 9.8 - CRITICAL | 2020-07-14 | 2023-11-07 |
| CVE-2020-1956 | Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user ... | 8.8 - HIGH | 2020-05-22 | 2023-11-07 |
| CVE-2020-1937 | Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malici... | 8.8 - HIGH | 2020-02-24 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Kylin | 4.0.0 | alpha | All | All |
| Application | Apache | Kylin | 3.1.0 | All | All | All |
| Application | Apache | Kylin | 3.0.2 | All | All | All |
| Application | Apache | Kylin | 3.0.1 | All | All | All |
| Application | Apache | Kylin | 3.0.0 | beta | All | All |
| Application | Apache | Kylin | 3.0.0 | alpha2 | All | All |
| Application | Apache | Kylin | 3.0.0 | alpha | All | All |
| Application | Apache | Kylin | 3.0.0 | - | All | All |
| Application | Apache | Kylin | 2.6.6 | All | All | All |
| Application | Apache | Kylin | 2.6.5 | All | All | All |
| Application | Apache | Kylin | 2.6.4 | All | All | All |
| Application | Apache | Kylin | 2.6.3 | All | All | All |
| Application | Apache | Kylin | 2.6.2 | All | All | All |
| Application | Apache | Kylin | 2.6.1 | All | All | All |
| Application | Apache | Kylin | 2.6.0 | All | All | All |
| Application | Apache | Kylin | 2.5.2 | All | All | All |
| Application | Apache | Kylin | 2.5.1 | All | All | All |
| Application | Apache | Kylin | 2.5.0 | All | All | All |
| Application | Apache | Kylin | 2.4.1 | All | All | All |
| Application | Apache | Kylin | 2.4.0 | All | All | All |