CVE-2025-66518: Apache Kyuubi: Unauthorized directory access due to missing path normalization
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.
This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.
Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66518?
CVE-2025-66518 is rated as a high severity vulnerability due to its potential to allow unauthorized file access.
How can I mitigate CVE-2025-66518?
To mitigate CVE-2025-66518, ensure that the kyuubi.session.local.dir.allow.list configuration only contains the necessary local directories.
Which versions of Apache Kyuubi are affected by CVE-2025-66518?
CVE-2025-66518 affects Apache Kyuubi versions from 1.6.0 to 1.10.2 inclusive.
What is the impact of exploiting CVE-2025-66518?
Exploiting CVE-2025-66518 can allow attackers to bypass session configuration and access local files not intended for use.
Has CVE-2025-66518 been addressed in any updates?
Check the latest Apache Kyuubi releases for patches related to CVE-2025-66518 to ensure protection against this vulnerability.