← Back to browse · API

CVE-2022-24697

Severity
CRITICAL
CVSS
9.8
EPSS
0.84777
Risk score
68.87
CISA KEV
No
PoC
No
Published
2022-10-13
Modified
2025-05-16
First seen
2026-08-07
Aliases
EUVD-2023-2116, GHSA-PPXX-M926-G569
Products
Apache Software Foundation:Apache Kylin Apache Kylin 2 <2.6.6, Apache Software Foundation:Apache Kylin Apache Kylin 3 ≤3.1.2, Apache Software Foundation:Apache Kylin Apache Kylin 4 ≤4.0.1
Sources
euvd EUVD-2023-2116

Description

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

References