Impact
Improper handling of permissions allows an attacker to retrieve job details that belong to other projects, exposing confidential execution data. The vulnerability arises from inadequate authorization checks during job information retrieval, categorised as CWE-280. If exploited, an attacker could view job metadata that should be restricted to authorized users. Based on the description, the likely attack vector is the job information retrieval endpoint accessed by a user lacking sufficient permissions.
Affected Systems
The flaw impacts Apache Kylin installations from version 4 through 5.0.3 inclusive. Any environment running these releases and exposing the job information endpoint is potentially vulnerable.
Risk and Exploitability
The EPSS score indicates a very low, yet non‑zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user with insufficient privileges accessing the job information endpoint, as inferred from the description. Remediation through an upgrade mitigates the risk entirely.
OpenCVE Enrichment