{"id":"GHSA-ppxx-m926-g569","summary":"Apache Kylin vulnerable to remote code execution","details":"Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.","aliases":["CVE-2022-24697"],"modified":"2025-05-16T22:37:55.472859Z","published":"2023-07-06T19:24:01Z","database_specific":{"cwe_ids":["CWE-77","CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-06T21:23:09Z","nvd_published_at":"2022-10-13T13:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24697"},{"type":"WEB","url":"https://github.com/apache/kylin/pull/1811"},{"type":"PACKAGE","url":"https://github.com/apache/kylin"},{"type":"WEB","url":"https://lists.apache.org/thread/07mnn9c7o314wrhrwjr10w9j5s82voj4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/12/30/1"}],"affected":[{"package":{"name":"org.apache.kylin:kylin-core-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.kylin/kylin-core-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.2"}]}],"versions":["1.5.0","1.5.1","1.5.2","1.5.2.1","1.5.3","1.5.4","1.5.4.1","1.6.0","2.0.0","2.1.0","2.2.0","2.3.0","2.3.1","2.3.2","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","3.0.0","3.0.0-alpha","3.0.0-alpha2","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","4.0.0","4.0.0-alpha","4.0.0-beta","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json"}},{"package":{"name":"org.apache.kylin:kylin-spark-project","ecosystem":"Maven","purl":"pkg:maven/org.apache.kylin/kylin-spark-project"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.2"}]}],"versions":["4.0.0","4.0.0-alpha","4.0.0-beta","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json"}},{"package":{"name":"org.apache.kylin:kylin-server-base","ecosystem":"Maven","purl":"pkg:maven/org.apache.kylin/kylin-server-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.2"}]}],"versions":["1.5.3","1.5.4","1.5.4.1","1.6.0","2.0.0","2.1.0","2.2.0","2.3.0","2.3.1","2.3.2","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","3.0.0","3.0.0-alpha","3.0.0-alpha2","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","4.0.0","4.0.0-alpha","4.0.0-beta","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}