← voltar
CVE-2022-24697criticalCWE-78

Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters

50Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 9.8epss 85%
probabilidade de exploração
85%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H