VendorsApachekylinall versions
Vulnerabilities

Apache Kylin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2020-13925
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely. Users of all previous versions after 2.3 should upgrade to 3.1.0.
Published 2020-07-14 · Modified
10.0EPSS 0.199
CVE-2021-45456
Command injection
Published 2022-01-06 · Modified
9.8EPSS 0.889
CVE-2022-24697
Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
Published 2022-10-13 · Modified
9.8EPSS 0.848
CVE-2022-44621
Apache Kylin: Command injection by Diagnosis Controller
Published 2022-12-30 · Modified
9.8EPSS 0.030
CVE-2021-31522
Apache Kylin unsafe class loading
Published 2022-01-06 · Modified
9.8EPSS 0.029
CVE-2026-62392
Apache Kylin: OS Command Injection via Async Query API
Published 2026-07-14 · Modified
9.8EPSS 0.025
CVE-2020-13926
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0.
Published 2020-07-14 · Modified
9.8EPSS 0.020
CVE-2026-62390
Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Published 2026-07-14 · Modified
9.8EPSS 0.007
CVE-2024-23590
Apache Kylin: Session fixation in web interface
Published 2024-11-04 · Analyzed
9.1EPSS 0.007
CVE-2020-1956
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
Published 2020-05-22 · Analyzed
9.0KEVEPSS 0.973
CVE-2022-43396
Apache Kylin: Command injection by Useless configuration
Published 2022-12-30 · Modified
8.8EPSS 0.553
CVE-2020-1937
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
Published 2020-02-24 · Modified
8.8EPSS 0.027
CVE-2025-61734
Apache Kylin: improper restriction of file read
Published 2025-10-02 · Modified
7.5EPSS 0.198
CVE-2021-27738
Improper Access Control to Streaming Coordinator & SSRF
Published 2022-01-06 · Modified
7.5EPSS 0.026
CVE-2021-45457
Overly broad CORS configuration
Published 2022-01-06 · Modified
7.5EPSS 0.024
CVE-2021-45458
Hardcoded credentials
Published 2022-01-06 · Modified
7.5EPSS 0.021
CVE-2025-61733
Apache Kylin: Authentication bypass
Published 2025-10-02 · Modified
7.5EPSS 0.013
CVE-2023-29055
Apache Kylin: Insufficiently protected credentials in config file
Published 2024-01-29 · Modified
7.5EPSS 0.011
CVE-2025-61735
Apache Kylin: Server-Side Request Forgery
Published 2025-10-02 · Modified
7.3EPSS 0.005
CVE-2025-30067
Apache Kylin: The remote code execution via jdbc url
Published 2025-03-27 · Analyzed
7.2EPSS 0.009
CVE-2021-36774
Mysql JDBC Connector Deserialize RCE
Published 2022-01-06 · Modified
6.5EPSS 0.019
CVE-2024-48944
Apache Kylin: SSRF vulnerability in the diagnosis api
Published 2025-03-27 · Analyzed
6.5EPSS 0.006
CVE-2020-13937
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
Published 2020-10-19 · Modified
5.3EPSS 0.783
CVE-2026-62393
Apache Kylin: Improper authorization in job information retrieval
Published 2026-07-14 · Modified
4.3EPSS 0.005