Описание
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Ссылки
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 5.0.4 (исключая)
cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00288
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-280
Связанные уязвимости
CVSS3: 4.3
github
29 дней назад
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
EPSS
Процентиль: 21%
0.00288
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-280