PT-2025-13037 · Apache · Apache Kylin
Pho3N1X
·
Published
2025-03-27
·
Updated
2025-04-11
·
CVE-2025-30067
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Kylin versions 4.0.0 through 5.0.1
Description
The issue is related to improper control of generation of code, also known as 'Code Injection'. If an attacker gains access to Kylin's system or project admin permission, they may alter the JDBC connection configuration to execute arbitrary code from a remote location. However, if Kylin's system and project admin access is well protected, the risk is mitigated.
Recommendations
For Apache Kylin versions 4.0.0 through 5.0.1, upgrade to version 5.0.2 or above to fix the issue.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Kylin