CVE-2021-45458

HIGH

Apache Kylin <2.6.6, <3.1.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to encrypt their password and configure it into kylin's configuration file, there is a risk that the password may be decrypted. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

Scores

CVSS v3 7.5
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-330 CWE-798
Status published
Products (3)
apache/kylin 4.0.0 (3 CPE variants)
apache/kylin 2.0.0 - 2.6.6
org.apache.kylin/kylin 0 - 3.1.3Maven
Published Jan 06, 2022
Tracked Since Feb 18, 2026