Apache Kylin Code Injection Vulnerability Allowing Remote Code Execution via JDBC Connection

Vulnerability

A code injection vulnerability has been identified in Apache Kylin versions 4.0.0 prior to 5.0.1. This vulnerability allows an attacker with system or project admin permissions to modify the JDBC connection settings, potentially executing arbitrary code from a remote source. The issue underscores the importance of safeguarding admin access in Kylin.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution on the server where Apache Kylin is running.

Remediation

Users are advised to upgrade to Apache Kylin version 5.0.2 or later, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.