CVE-2021-45458: Hardcoded credentials
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to encrypt their password and configure it into kylin's configuration file, there is a risk that the password may be decrypted. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45458?
CVE-2021-45458 is a vulnerability in Apache Kylin that allows users' encrypted passwords to be easily decrypted.
How does Apache Kylin encryption class PasswordPlaceholderConfigurer work?
Apache Kylin encryption class PasswordPlaceholderConfigurer helps users encrypt their passwords.
What is the severity of CVE-2021-45458?
The severity of CVE-2021-45458 is high, with a CVSS score of 7.5.
Which versions of Apache Kylin are affected by CVE-2021-45458?
The versions affected by CVE-2021-45458 range from 2.0.0 to 2.6.6, 3.0.0 to 3.1.3, 4.0.0-alpha, 4.0.0-beta, and 4.0.0.
How can I fix CVE-2021-45458?
To fix CVE-2021-45458, users should update to version 4.0.1 for Apache Kylin or version 3.1.3 for the maven package org.apache.kylin:kylin.