Command Injection Affecting org.apache.kylin:kylin-server package, versions [2.3.0, 3.1.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.64% (80th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Command Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHEKYLIN-584373
  • published14 Jul 2020
  • disclosed14 Jul 2020
  • creditClancey

Introduced: 14 Jul 2020

CVE-2020-13925  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade org.apache.kylin:kylin-server to version 3.1.0 or higher.

Overview

org.apache.kylin:kylin-server is an analytics Engine, contributed by eBay Inc., provides SQL interface and multi-dimensional analysis (OLAP) on Hadoop supporting extremely large datasets.

Affected versions of this package are vulnerable to Command Injection. It one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely.

CVSS Scores

version 3.1