CVE-2021-36774

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-36774
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-36774.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-36774
Aliases
Published
2022-01-06T13:15:08Z
Modified
2024-09-02T22:12:06Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Kylin server processes. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions.

References

Affected packages

Git / github.com/apache/kylin

Affected ranges