National Cyber Warfare Foundation (NCWF)

CVE-2021-45456


0 user ratings
2021-12-21 00:00:00
milo
CVEs

 - archive -- 

CVE-2021-45456

Date: 2021-12-21

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal project name to pass the check and perform the following steps, resulting in a command injection vulnerability. This issue affects Apache Kylin 4.0.0.



References:




Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.