endpoint open for service.
This issue affects Apache Kylin: from 5.0.0
through
5.0.1.
Users are recommended to upgrade to version 5.0.2, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8498 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another internal host has the "/kylin/api/xxx/diag" api endpoint open for service. This issue affects Apache Kylin: from 5.0.0 through 5.0.1. Users are recommended to upgrade to version 5.0.2, which fixes the issue. |
Github GHSA |
GHSA-3v67-545x-ffc3 | Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint |
Tue, 01 Apr 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache kylin |
|
| CPEs | cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache kylin |
Thu, 27 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 27 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 27 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another internal host has the "/kylin/api/xxx/diag" api endpoint open for service. This issue affects Apache Kylin: from 5.0.0 through 5.0.1. Users are recommended to upgrade to version 5.0.2, which fixes the issue. | |
| Title | Apache Kylin: SSRF vulnerability in the diagnosis api | |
| Weaknesses | CWE-918 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-08T10:26:40.785Z
Reserved: 2024-10-09T23:49:24.489Z
Link: CVE-2024-48944
Updated: 2025-03-27T16:04:00.577Z
Status : Analyzed
Published: 2025-03-27T15:15:53.573
Modified: 2025-04-01T15:44:43.393
Link: CVE-2024-48944
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA