In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-184 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-11T14:49:56.691Z
Reserved: 2022-10-18T08:30:30.500Z
Link: CVE-2022-43396

Updated: 2024-08-03T13:32:59.631Z

Status : Modified
Published: 2022-12-30T11:15:10.407
Modified: 2025-04-11T15:15:39.980
Link: CVE-2022-43396

No data.