PT-2022-1875 · Apache · Apache Kylin

Alvaro Munoz

·

Published

2022-01-06

·

Updated

2022-01-13

·

CVE-2021-45456

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Kylin version 4.0.0
Description The issue is related to a command injection vulnerability due to a mismatch between the checked and used project name in the DiagnosisService. This may allow an attacker to execute arbitrary commands by passing an illegal project name. The vulnerability is associated with a lack of input data sanitization.
Recommendations For Apache Kylin version 4.0.0, update to a version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01379
CVE-2021-45456
GHSA-HW3M-8H25-8FRW

Affected Products

Apache Kylin