CVE-2022-44621: Apache Kylin: Command injection by Diagnosis Controller
Published Dec 30, 2022
·Updated
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Affected Software
1 affected component
Apache kylin<4.0.3
Remediation
Event History
Dec 30, 2022
CVE Published
via MITRE·10:31 AM
Data Sourced
via MITRE·10:31 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-44621?
CVE-2022-44621 is a vulnerability in Apache Kylin, specifically in the Diagnosis Controller. It allows an attacker to execute commands via HTTP request due to the lack of parameter validation.
2
How severe is CVE-2022-44621?
CVE-2022-44621 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-44621 impact Apache Kylin?
CVE-2022-44621 affects Apache Kylin by enabling an attacker to perform command injection through HTTP requests.
4
Which version of Apache Kylin is affected by CVE-2022-44621?
Apache Kylin version up to 4.0.3 is affected by CVE-2022-44621.
5
Is there a fix available for CVE-2022-44621?
The fix for CVE-2022-44621 is not mentioned in the provided information, but it is recommended to update Apache Kylin to the latest version to mitigate this vulnerability.