VYPR

Kylin

by Apache

Source repositories

CVEs (24)

  • CVE-2021-45457HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

  • CVE-2021-36774MedJan 6, 2022
    risk 0.00cvss 6.5epss 0.02

    Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Kylin server…

  • CVE-2021-31522CriJan 6, 2022
    risk 0.00cvss 9.8epss 0.03

    Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

  • CVE-2021-27738HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.03

    All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning of streaming…

Page 2 of 2