CyberRota Analysis
AI-GeneratedApache Kylin versions 4 through 5.0.3 are vulnerable to an OS Command Injection flaw, allowing attackers to manipulate backend API job configuration parameters and execute arbitrary OS commands. This critical vulnerability, with a CVSS score of 9.8, poses significant risks to system integrity and data security. Organizations using affected versions should prioritize upgrading to version 5.0.4 to mitigate potential exploitation.
Original NVD Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)