In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2022-12-30T10:30:45.627Z
Updated: 2024-08-03T13:32:59.631Z
Reserved: 2022-10-18T08:30:30.500Z
Link: CVE-2022-43396
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-30T11:15:10.407
Modified: 2024-11-21T07:26:23.897
Link: CVE-2022-43396
Redhat
No data.