Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv75-pcv7-p758

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.

This issue affects Apache Kylin: from 4 through 5.0.3.

Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.

This issue affects Apache Kylin: from 4 through 5.0.3.

Users are recommended to upgrade to version 5.0.4, which fixes the issue.

EPSS

Процентиль: 68%
0.01321
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
29 дней назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

EPSS

Процентиль: 68%
0.01321
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78