Apache Kylin vulnerable to Command injection by Useless configuration
High severity
GitHub Reviewed
Published
Dec 30, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Dec 30, 2022
Published to the GitHub Advisory Database
Dec 30, 2022
Reviewed
Jan 3, 2023
Last updated
Feb 3, 2023
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the
kylin.engine.spark-cmd
parameter ofconf
.References