Vulnerability record · CVE-2021-45456 · published 6 January 2022
CVE-2021-45456: Apache Kylin DiagnosisService project name check mismatch allows command injection
Apache · Kylin
Apache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell command argument. An illegal project name can therefore pass validation and be executed as a shell command, yielding command injection. Only Apache Kylin 4.0.0 is stated as affected.
Description
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal project name to pass the check and perform the following steps, resulting in a command injection vulnerability. This issue affects Apache Kylin 4.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and very high EPSS make this a top remediation priority despite the lack of KEV listing.
What it is
Apache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell command argument. An illegal project name can therefore pass validation and be executed as a shell command, yielding command injection. Only Apache Kylin 4.0.0 is stated as affected.
Impact
An attacker can execute arbitrary shell commands on the Kylin host, leading to full compromise of confidentiality, integrity and availability of the server and its data.
Attack surface
Reachable over the network through the DiagnosisService endpoint that accepts a project name; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.889, 99.8th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Apache Kylin 4.0.0 to a fixed release as soon as the vendor patch is available.
- Restrict network access to the Kylin DiagnosisService and administrative interfaces to trusted hosts only.
- Enforce strict allowlist validation of project names at the application layer, independent of the flawed check.
- Run Kylin with least privilege and avoid shell invocation for project-name handling where possible.
- Monitor vendor advisories for updated fixed versions and backports.
Detection
- Audit Kylin logs for DiagnosisService requests containing shell metacharacters or unexpected project names.
- Alert on child processes spawned by the Kylin JVM (e.g., sh, bash, curl, wget) that are not part of normal operation.
- Monitor outbound network connections from Kylin hosts for signs of post-exploitation activity.
- Review access logs for unauthenticated requests to diagnosis or project-related endpoints from unusual sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/01/06/1 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/70fkf9w1swt2cqdcz13rwfjvblw1fcpf | Mailing ListVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/06/1 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/70fkf9w1swt2cqdcz13rwfjvblw1fcpf | Mailing ListVendor Advisory |
Track CVE-2021-45456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-45456), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.