GHSA-q656-g2x3-8cgh
Dashboard / Vulnerabilities / GHSA-q656-g2x3-8cgh
Summary: Kylin can receive user input and load any class through Class.forName(...).
Details: Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-31522, https://github.com/apache/kylin/pull/1695, https://github.com/apache/kylin/pull/1763, https://github.com/apache/kylin, https://lists.apache.org/thread/hh5crx3yr701zd8wtpqo1mww2rlkvznw, http://www.openwall.com/lists/oss-security/2022/01/06/4
Affected packages
Package
Name: org.apache.kylin:kylin
Purl: pkg:maven/org.apache.kylin/kylin
Affected ranges
Type: ECOSYSTEM
Events:
