{"id":"CVE-2022-43396","summary":"Apache Kylin: Command injection by Useless configuration","details":"In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.","aliases":["GHSA-f5q9-j9r2-34gq"],"modified":"2026-08-12T03:51:36.412827786Z","published":"2022-12-30T10:30:45.627Z","database_specific":{"cna_assigner":"apache","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43396.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Apache Kylin 4"},{"last_affected":"4.0.2"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43396.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/ob2ks04zl5ms0r44cd74y1xdl1rzfd1r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-43396"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/kylin","events":[{"introduced":"0"},{"fixed":"322ab6e5ee9738c5a07165af398c1faeeeacb079"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.0.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*"}}],"versions":["kylin-4.0.2","kylin-4.0.0-beta","kylin-4.0.0-alpha","v0.6.1_mysql_auth","v0.6.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43396.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}