Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
Session Fixation attack works by forcing a victim to use a pre-known session identifier before authentication. The application does not generate a new session identifier after successful user login, as a result the authenticated session remains associated with an identifier controlled by the attacker. After the victim logs in using the imposed identifier, the attacker can use it to gain full access to their account.
An attacker can hijack the session of an authenticated user, gaining access to their data and the ability to perform operations on their behalf, including reading and modifying analytical data stored in Apache Kylin.
Apache Kylin should be updated to version 5.0.0 or later, which contains a fix that eliminates this vulnerability.
Apache Kylin versions 2.0.0 through 4.x inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Kylin
APPApache2.0.0 – 5.0.0 (excl.)
Related vulnerabilities
OS Command Injection w Apache Kylin — nieautoryzowane wykonanie poleceń
Apache Kylin — command injection w Diagnosis Controller via HTTP
Apache Kylin — Command Injection w funkcji projektanta kostek (RCE)
Apache Kylin — dynamiczne ładowanie klas przez niezaufane dane wejściowe
Command injection w Apache Kylin poprzez nazwę projektu