Apache Kylin
cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*
- >= 4.0.0, <= 5.0.1
A code injection vulnerability has been identified in Apache Kylin versions 4.0.0 prior to 5.0.1. This vulnerability allows an attacker with system or project admin permissions to modify the JDBC connection settings, potentially executing arbitrary code from a remote source. The issue underscores the importance of safeguarding admin access in Kylin.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the server where Apache Kylin is running.
Users are advised to upgrade to Apache Kylin version 5.0.2 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.