Apache kylin是美国Apache基金会开源的一个大数据分析引擎。 Apache Kylin存在命令注入漏洞,该漏洞可能导致后端API将作业配置参数引入OS命令行。以下版本受到影响:4.0.0版本、4.0.3版本、4.0.4版本、5.0.0版本、5.0.1版本、5.0.2版本和5.0.3版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Kylin | 4≤ 5.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Kylin | 4 ~ 5.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49488 | Apache OpenMeetings: Arbitrary File Read | |
| CVE-2026-62393 | Apache Kylin: Improper authorization in job information retrieval | |
| CVE-2026-62390 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API | |
| CVE-2026-58319 | Apache Doris: Improper Authentication in Frontend HTTP API | |
| CVE-2026-59084 | Apache Tomcat: EncryptInterceptor requirements not clearly documented | |
| CVE-2026-59083 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass |
No comments yet