https://seclists.org/oss-sec/2025/q1/251: CVE-2025-30067: Apache Kylin: The mote code execution via jdbc url
Published Mar 27, 2025
·Updated
Affected Software
1 affected component
Apache kylin>=4.0.0<=5.0.1
Frequently Asked Questions
1
What is the severity of CVE-2025-30067?
The severity of CVE-2025-30067 is classified as low.
2
What versions of Apache Kylin are affected by CVE-2025-30067?
CVE-2025-30067 affects Apache Kylin versions 4.0.0 through 5.0.1.
3
How do I fix CVE-2025-30067?
To fix CVE-2025-30067, ensure that users do not have unnecessary system or project admin permissions and validate JDBC connection configurations.
4
What type of vulnerability is CVE-2025-30067?
CVE-2025-30067 is an improper control of generation of code vulnerability primarily categorized as a code injection issue.
5
What can an attacker do with CVE-2025-30067?
An attacker with access to Kylin's system or project admin permission can alter the JDBC connection configuration to execute arbitrary code.