Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
Published Oct 13, 2022
9.8
CRITICALCVSS 3.1
EPSS 84.78%
Description
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.
Affected products
-
- Version Apache Kylin 2StatusaffectedConstraints<2.6.6
- Version Apache Kylin 3StatusaffectedConstraints<=3.1.2
- Version Apache Kylin 4StatusaffectedConstraints<=4.0.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Kylin | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Users of Kylin 2.x & Kylin 3.x & 4.x should upgrade to 4.0.2 or apply patch https://github.com/apache/kylin/pull/1811 .
References (5)
- http://www.openwall.com/lists/oss-security/2022/12/30/1 mailing-listMailing ListPatchThird Party Advisory
- https://github.com/advisories/GHSA-ppxx-m926-g569 Advisory
- https://github.com/apache/kylin/pull/1811
- https://lists.apache.org/thread/07mnn9c7o314wrhrwjr10w9j5s82voj4 Mailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24697
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/12/30/1 | mailing-listMailing ListPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-ppxx-m926-g569 | Advisory | |
| https://github.com/apache/kylin/pull/1811 | ||
| https://lists.apache.org/thread/07mnn9c7o314wrhrwjr10w9j5s82voj4 | Mailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-24697 |
Change history (0)
No recorded changes yet.