CVE-2022-24697

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24697
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24697.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24697
Aliases
Published
2022-10-13T13:15:09Z
Modified
2025-05-16T14:15:27Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

References

Affected packages

Git / github.com/apache/kylin

Affected ranges

Type
GIT
Repo
https://github.com/apache/kylin
Events