Severity: important

Description:

Kylin's cube designer function has a command injection vulnerability when 
overwriting system parameters in the configuration overwrites menu. RCE can be 
implemented by closing the single quotation marks around the parameter value of 
“-- conf=” to inject any operating system command into the command line 
parameters. This vulnerability affects the kylin which version is 4.0.1 and 
above.

Mitigation:

Users of Kylin 2.x & Kylin 3.x & 4.x should upgrade to 4.0.2 or apply patch 
https://github.com/apache/kylin/pull/1811 .

Credit:

Kylin Team would like to thanks Kai Zhao of ToTU Secruity Team.

Reply via email to