CVE-2022-43396: Apache Kylin vulnerable to Command injection by Useless configuration
(updated )
In the fix for CVE-2022-24697, a block list is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
References
Detect and mitigate CVE-2022-43396 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →