CVE-2025-30067

HIGH

Apache Kylin <5.0.1 - Code Injection

Title source: llm
STIX 2.1

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.1. Users are recommended to upgrade to version 5.0.2 or above, which fixes the issue.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/03/27/4
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/6j19pt8yoqfphf1lprtrzoqkvz1gwbnc

Scores

CVSS v3 7.2
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
apache/kylin 4.0.0 - 5.0.2
org.apache.kylin/kylin 4.0.0 - 5.0.2Maven
Published Mar 27, 2025
Tracked Since Feb 18, 2026