Executive brief
Apache Kylin contains an OS command injection vulnerability in its RESTful APIs. The vulnerability occurs because user input is concatenated directly into OS commands without proper validation, allowing an authenticated attacker to execute arbitrary commands on the underlying system.
Affected products
- Apache Kylin 2.3.0 to 2.6.5, 3.0.0 to 3.0.1
Timeline
- 2020-07-14: disclosed: Initial public disclosure via oss-security mailing list
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog