PT-2022-1875 · Apache · Apache Kylin
Alvaro Munoz
·
Published
2022-01-06
·
Updated
2022-01-13
·
CVE-2021-45456
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Kylin version 4.0.0
Description
The issue is related to a command injection vulnerability due to a mismatch between the checked and used project name in the DiagnosisService. This may allow an attacker to execute arbitrary commands by passing an illegal project name. The vulnerability is associated with a lack of input data sanitization.
Recommendations
For Apache Kylin version 4.0.0, update to a version that includes a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Kylin