CVE-2024-48944 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on…
Medium CVSS: 6.5

CVE-2024-48944

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another internal host has the "/kylin/api/xxx/diag" api

endpoint open for service.


This issue affects Apache Kylin: from 5.0.0
through

5.0.1.

Users are recommended to upgrade to version 5.0.2, which fixes the issue.
Vendor
Apache
Product
Kylin
CWE
CWE-918
Yayın Tarihi
2025-03-27 15:15:53
Güncelleme
2025-04-01 15:44:43
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar