GHSA-9fj5-jg6f-qg5r

Suggest an improvement
Source
https://github.com/advisories/GHSA-9fj5-jg6f-qg5r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-9fj5-jg6f-qg5r/GHSA-9fj5-jg6f-qg5r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9fj5-jg6f-qg5r
Aliases
Published
2022-01-08T00:43:09Z
Modified
2024-02-16T08:04:29.797652Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Use of Hard-coded Credentials in Apache Kylin
Details

Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to encrypt their password and configure it into kylin's configuration file, there is a risk that the password may be decrypted. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

Database specific
{
    "nvd_published_at": "2022-01-06T13:15:00Z",
    "cwe_ids": [
        "CWE-326",
        "CWE-330",
        "CWE-798"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-01-07T22:53:35Z"
}
References

Affected packages

Maven / org.apache.kylin:kylin

Package

Name
org.apache.kylin:kylin
View open source insights on deps.dev
Purl
pkg:maven/org.apache.kylin/kylin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.3

Affected versions

0.*

0.7.1-incubating
0.7.2-incubating

1.*

1.0-incubating
1.1-incubating
1.1.1-incubating
1.2
1.3.0
1.5.0
1.5.1
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.0

2.*

2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6

3.*

3.0.0-alpha
3.0.0-alpha2
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2

Maven / org.apache.kylin:kylin

Package

Name
org.apache.kylin:kylin
View open source insights on deps.dev
Purl
pkg:maven/org.apache.kylin/kylin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0