Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44621


Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.


Published

2022-12-30T11:15:10.467

Last Modified

2025-04-11T15:15:40.140

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache kylin < 4.0.3 Yes

References