Apache Kylin
Apache · 20 CVEs
Apache Kylin: Improper authorization in job information retrieval
Jul 14, 2026
Apache Kylin: OS Command Injection via Async Query API
Jul 14, 2026
Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Jul 14, 2026
Apache Kylin: Server-Side Request Forgery
Oct 2, 2025
Apache Kylin: Authentication bypass
Oct 2, 2025
Apache Kylin: improper restriction of file read
Oct 2, 2025
Apache Kylin: The remote code execution via jdbc url
Mar 27, 2025
Apache Kylin: SSRF vulnerability in the diagnosis api
Mar 27, 2025
Apache Kylin: Session fixation in web interface
Nov 4, 2024
Apache Kylin: Insufficiently protected credentials in config file
Jan 29, 2024
Apache Kylin: Command injection by Diagnosis Controller
Dec 30, 2022
Apache Kylin: Command injection by Useless configuration
Dec 30, 2022
Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system param…
Oct 13, 2022
Hardcoded credentials
Jan 6, 2022
Overly broad CORS configuration
Jan 6, 2022
Command injection
Jan 6, 2022
Mysql JDBC Connector Deserialize RCE
Jan 6, 2022
Apache Kylin unsafe class loading
Jan 6, 2022
Improper Access Control to Streaming Coordinator & SSRF
Jan 6, 2022
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run…
Feb 24, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-62393 | Apache Kylin: Improper authorization in job information retrieval | MEDIUM | 0.45% | Jul 14, 2026 |
| CVE-2026-62392 | Apache Kylin: OS Command Injection via Async Query API | CRITICAL | 2.48% | Jul 14, 2026 |
| CVE-2026-62390 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API | CRITICAL | 0.69% | Jul 14, 2026 |
| CVE-2025-61735 | Apache Kylin: Server-Side Request Forgery | HIGH | 0.53% | Oct 2, 2025 |
| CVE-2025-61733 | Apache Kylin: Authentication bypass | HIGH | 1.30% | Oct 2, 2025 |
| CVE-2025-61734 | Apache Kylin: improper restriction of file read | HIGH | 19.78% | Oct 2, 2025 |
| CVE-2025-30067 | Apache Kylin: The remote code execution via jdbc url | LOW | 0.93% | Mar 27, 2025 |
| CVE-2024-48944 | Apache Kylin: SSRF vulnerability in the diagnosis api | LOW | 0.63% | Mar 27, 2025 |
| CVE-2024-23590 | Apache Kylin: Session fixation in web interface | HIGH | 0.67% | Nov 4, 2024 |
| CVE-2023-29055 | Apache Kylin: Insufficiently protected credentials in config file | HIGH | 1.15% | Jan 29, 2024 |
| CVE-2022-44621 | Apache Kylin: Command injection by Diagnosis Controller | CRITICAL | 2.99% | Dec 30, 2022 |
| CVE-2022-43396 | Apache Kylin: Command injection by Useless configuration | HIGH | 55.28% | Dec 30, 2022 |
| CVE-2022-24697 | Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters | CRITICAL | 84.78% | Oct 13, 2022 |
| CVE-2021-45458 | Hardcoded credentials | HIGH | 2.08% | Jan 6, 2022 |
| CVE-2021-45457 | Overly broad CORS configuration | HIGH | 2.38% | Jan 6, 2022 |
| CVE-2021-45456 | Command injection | CRITICAL | 88.89% | Jan 6, 2022 |
| CVE-2021-36774 | Mysql JDBC Connector Deserialize RCE | MEDIUM | 1.95% | Jan 6, 2022 |
| CVE-2021-31522 | Apache Kylin unsafe class loading | CRITICAL | 2.90% | Jan 6, 2022 |
| CVE-2021-27738 | Improper Access Control to Streaming Coordinator & SSRF | HIGH | 2.56% | Jan 6, 2022 |
| CVE-2020-1937 | Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. | HIGH | 3.07% | Feb 24, 2020 |
Showing 1 to 20 of 20 CVEs