OS Command Injection in Apache Kylin - CVE-2021-45456

 

OS Command Injection in Apache Kylin - CVE-2021-45456

Published: January 6, 2022


Vulnerability identifier: #VU59274
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45456
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exist due to improper input validation when processing project names. A remote user can pass a specially crafted project name that is later passed as the shell command argument in DiagnosisService and execute arbitrary OS commands on the system.

Affected software

Apache Kylin

How to mitigate CVE-2021-45456

Install updates from vendor's website.

Apache Kylin - update to 4.0.1

External References

Related Security Bulletins