AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-30067

HIGH · CVSS 7.2 EPSS 0.82%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-03-27 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.2. It affects Apache. It may be remotely exploitable.

CVE
CVE-2025-30067
Severity
HIGH
CVSS
7.2
EPSS
0.82%
Apache

Original NVD Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.1. Users are recommended to upgrade to version 5.0.2 or above, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)