cbcvebase.

Apache Kylin vulnerabilities

24 known vulnerabilities affecting apache/kylin.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH11MEDIUM4

Vulnerabilities

Page 2 of 2
CVE-2021-45457P3HIGHCVSS 7.5≥ 2.0.0, ≤ 2.6.6≥ 3.0.0, < 3.1.3+1 more2022-01-06
CVE-2021-45457 [HIGH] CWE-863 CVE-2021-45457: In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
nvd
CVE-2021-36774P3MEDIUMCVSS 6.5≥ 2.0.0, ≤ 2.6.6≥ 3.0.0, ≤ 3.1.22022-01-06
CVE-2021-36774 [MEDIUM] CVE-2021-36774: Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Kylin server processes. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache
nvd
CVE-2024-48944P3MEDIUMCVSS 6.5≥ 5.0.0, < 5.0.22025-03-27
CVE-2024-48944 [MEDIUM] CWE-918 CVE-2024-48944: Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacke Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another internal host has the "/kylin/api/x
nvd
CVE-2026-62393P4MEDIUMCVSS 4.3≥ 4.0.0, < 5.0.42026-07-14
CVE-2026-62393 [MEDIUM] CWE-280 CVE-2026-62393: Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
nvd
Apache Kylin vulnerabilities | cvebase