Showing 1 vulnerability on this page for Kylin

Signals CISA KEV Ransomware Nuclei
apache vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Command Injection in Kylin

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

CWE-78May 22, 20201 related artifact
CVSS8.8v3.1EPSS97.3%PoCs1SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX