Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
CVE-2022-24697
What is CVE-2022-24697?
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of โ-- conf=โ to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Kylin Apache Kylin 2 < 2.6.6
Apache Kylin Apache Kylin 3 <= 3.1.2
Apache Kylin Apache Kylin 4 <= 4.0.1
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved