org.apache.kylin:kylin-core-common vulnerabilities

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.apache.kylin:kylin-core-common package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Authentication Bypass Using an Alternate Path or Channel

[4.0.0,5.0.3)
  • M
Files or Directories Accessible to External Parties

[4.0.0,5.0.3)
  • M
Server-side Request Forgery (SSRF)

[4.0.0,5.0.3)
  • L
Server-side Request Forgery (SSRF)

[5.0.0,5.0.2)
  • L
Arbitrary Code Injection

[4.0.0,5.0.2)
  • M
Insufficiently Protected Credentials

[2.0.0,4.0.4)
  • H
Command Injection

[2.0.0,4.0.3)
  • H
Remote Code Execution (RCE)

[2.0.0,4.0.2)
  • M
Insecure Encryption

[,3.1.3)[4.0.0-alpha,4.0.1)
  • H
Arbitrary Code Execution

[,3.1.3)
  • M
Cryptographic Issues

[,kylin-3.1.0)
  • H
Command Injection

[2.3.0,2.3.2)[2.4.0,2.4.1)[2.5.0,2.5.2)[2.6.0,2.6.5)

Package versions

47 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.0.318 Sep, 2025
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
5.0.211 Mar, 2025
  • 1
    C
  • 0
    H
  • 3
    M
  • 0
    L
5.0.014 Sep, 2024
  • 1
    C
  • 0
    H
  • 3
    M
  • 2
    L
5.0.0-beta23 Aug, 2023
  • 1
    C
  • 0
    H
  • 3
    M
  • 1
    L
5.0.0-alpha21 Apr, 2023
  • 1
    C
  • 0
    H
  • 3
    M
  • 1
    L
4.0.420 Jan, 2024
  • 1
    C
  • 0
    H
  • 3
    M
  • 1
    L
4.0.316 Dec, 2022
  • 1
    C
  • 0
    H
  • 4
    M
  • 1
    L
4.0.228 Aug, 2022
  • 1
    C
  • 1
    H
  • 4
    M
  • 1
    L
4.0.129 Dec, 2021
  • 1
    C
  • 2
    H
  • 4
    M
  • 1
    L
4.0.023 Aug, 2021
  • 1
    C
  • 2
    H
  • 5
    M
  • 1
    L