CVE-2022-44621

CWE-77Command Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
9.2%
top 7.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/kylin< 4.0.3
Mavenorg.apache.kylin:kylin-server-base2.0.04.0.3
CVEListV5apache_software_foundation/apache_kylinApache Kylin 4 4.0.2

Patches

🔴Vulnerability Details

3
CVEList
Apache Kylin: Command injection by Diagnosis Controller2022-12-30
GHSA
Apache Kylin vulnerable to Command injection by Diagnosis Controller2022-12-30
OSV
Apache Kylin vulnerable to Command injection by Diagnosis Controller2022-12-30