Apache Kylin

Apache · 20 CVEs

CVE-2026-62393
MEDIUM

Apache Kylin: Improper authorization in job information retrieval

Jul 14, 2026

CVE-2026-62392
CRITICAL

Apache Kylin: OS Command Injection via Async Query API

Jul 14, 2026

CVE-2026-62390
CRITICAL

Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API

Jul 14, 2026

CVE-2025-61735
HIGH

Apache Kylin: Server-Side Request Forgery

Oct 2, 2025

CVE-2025-61733
HIGH

Apache Kylin: Authentication bypass

Oct 2, 2025

CVE-2025-61734
HIGH

Apache Kylin: improper restriction of file read

Oct 2, 2025

CVE-2025-30067
LOW

Apache Kylin: The remote code execution via jdbc url

Mar 27, 2025

CVE-2024-48944
LOW

Apache Kylin: SSRF vulnerability in the diagnosis api

Mar 27, 2025

CVE-2024-23590
HIGH

Apache Kylin: Session fixation in web interface

Nov 4, 2024

CVE-2023-29055
HIGH

Apache Kylin: Insufficiently protected credentials in config file

Jan 29, 2024

CVE-2022-44621
CRITICAL

Apache Kylin: Command injection by Diagnosis Controller

Dec 30, 2022

CVE-2022-43396
HIGH

Apache Kylin: Command injection by Useless configuration

Dec 30, 2022

CVE-2022-24697
CRITICAL

Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system param…

Oct 13, 2022

CVE-2021-45458
HIGH

Hardcoded credentials

Jan 6, 2022

CVE-2021-45457
HIGH

Overly broad CORS configuration

Jan 6, 2022

CVE-2021-45456
CRITICAL

Command injection

Jan 6, 2022

CVE-2021-36774
MEDIUM

Mysql JDBC Connector Deserialize RCE

Jan 6, 2022

CVE-2021-31522
CRITICAL

Apache Kylin unsafe class loading

Jan 6, 2022

CVE-2021-27738
HIGH

Improper Access Control to Streaming Coordinator & SSRF

Jan 6, 2022

CVE-2020-1937
HIGH

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run…

Feb 24, 2020

Showing 1 to 20 of 20 CVEs