VYPR
Critical severity9.8NVD Advisory· Published Oct 13, 2022· Updated Jun 17, 2026

CVE-2022-24697

CVE-2022-24697

Description

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.kylin:kylin-core-commonMaven
< 4.0.24.0.2
org.apache.kylin:kylin-spark-projectMaven
< 4.0.24.0.2
org.apache.kylin:kylin-server-baseMaven
< 4.0.24.0.2

Affected products

5

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.