CRITICAL🇵🇱 Wersja polska

CVE-2024-23590

CVSS 9.1v3.1pub. 2024-11-04upd. 2025-07-10

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.

🤖 AI Analysis
How it works

Session Fixation attack works by forcing a victim to use a pre-known session identifier before authentication. The application does not generate a new session identifier after successful user login, as a result the authenticated session remains associated with an identifier controlled by the attacker. After the victim logs in using the imposed identifier, the attacker can use it to gain full access to their account.

Impact

An attacker can hijack the session of an authenticated user, gaining access to their data and the ability to perform operations on their behalf, including reading and modifying analytical data stored in Apache Kylin.

Mitigation & patch

Apache Kylin should be updated to version 5.0.0 or later, which contains a fix that eliminates this vulnerability.

Who is affected

Apache Kylin versions 2.0.0 through 4.x inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Kylin

    APP
    Apache
    2.0.0 – 5.0.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-62392CRITICAL9.8PL ✓same product

OS Command Injection w Apache Kylin — nieautoryzowane wykonanie poleceń

CVE-2022-44621CRITICAL9.8PL ✓same product

Apache Kylin — command injection w Diagnosis Controller via HTTP

CVE-2022-24697CRITICAL9.8PL ✓same product

Apache Kylin — Command Injection w funkcji projektanta kostek (RCE)

CVE-2021-31522CRITICAL9.8PL ✓same product

Apache Kylin — dynamiczne ładowanie klas przez niezaufane dane wejściowe

CVE-2021-45456CRITICAL9.8PL ✓same product

Command injection w Apache Kylin poprzez nazwę projektu