CVE-2021-45457: Overly broad CORS configuration
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45457?
CVE-2021-45457 is a vulnerability in Apache Kylin that allows cross-origin requests with credentials from any origin.
Which versions of Apache Kylin are affected by CVE-2021-45457?
CVE-2021-45457 affects Apache Kylin 2 version 2.6.6 and prior, Apache Kylin 3 version 3.1.2 and prior, Apache Kylin 4 version 4.0.0 and prior.
What is the severity of CVE-2021-45457?
CVE-2021-45457 has a severity score of 7.5 (high).
How can I fix CVE-2021-45457?
To fix CVE-2021-45457, upgrade to a version of Apache Kylin that is not affected by the vulnerability.
Where can I find more information about CVE-2021-45457?
You can find more information about CVE-2021-45457 on the following references: [http://www.openwall.com/lists/oss-security/2022/01/06/2](http://www.openwall.com/lists/oss-security/2022/01/06/2), [https://lists.apache.org/thread/rzv4mq58okwj1n88lry82ol2wwm57q1m](https://lists.apache.org/thread/rzv4mq58okwj1n88lry82ol2wwm57q1m).