Apache Kylin vulnerable to Command injection by Useless configuration
High severity
GitHub Reviewed
Published
Dec 30, 2022
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Dec 30, 2022
Published to the GitHub Advisory Database
Dec 30, 2022
Reviewed
Jan 3, 2023
Last updated
Apr 11, 2025
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the
kylin.engine.spark-cmd
parameter ofconf
.References