VYPR
Critical severity9.8NVD Advisory· Published Jan 6, 2022· Updated Jun 17, 2026

CVE-2021-31522

CVE-2021-31522

Description

Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.kylin:kylinMaven
< 3.1.33.1.3
org.apache.kylin:kylinMaven
>= 4.0.0, < 4.0.14.0.1

Affected products

6
  • Apache/Kylin4 versions
    cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.6.6
    • cpe:2.3:a:apache:kylin:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:apache:kylin:4.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:kylin:4.0.0:beta:*:*:*:*:*:*
  • ghsa-coords
    Range: < 3.1.3
  • Apache Software Foundation/Apache Kylinv5
    Range: Apache Kylin 2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.