← Vulnerability feed

Vulnerability record · CVE-2021-45456 · published 6 January 2022

CVE-2021-45456: Apache Kylin DiagnosisService project name check mismatch allows command injection

Apache · Kylin

Apache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell command argument. An illegal project name can therefore pass validation and be executed as a shell command, yielding command injection. Only Apache Kylin 4.0.0 is stated as affected.

9.8 CVSS 3.1 Critical EPSS 89% · top 0.2% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal project name to pass the check and perform the following steps, resulting in a command injection vulnerability. This issue affects Apache Kylin 4.0.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required and very high EPSS make this a top remediation priority despite the lack of KEV listing.

What it is

Apache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell command argument. An illegal project name can therefore pass validation and be executed as a shell command, yielding command injection. Only Apache Kylin 4.0.0 is stated as affected.

Impact

An attacker can execute arbitrary shell commands on the Kylin host, leading to full compromise of confidentiality, integrity and availability of the server and its data.

Attack surface

Reachable over the network through the DiagnosisService endpoint that accepts a project name; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.889, 99.8th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Apache Kylin 4.0.0 to a fixed release as soon as the vendor patch is available.
  • Restrict network access to the Kylin DiagnosisService and administrative interfaces to trusted hosts only.
  • Enforce strict allowlist validation of project names at the application layer, independent of the flawed check.
  • Run Kylin with least privilege and avoid shell invocation for project-name handling where possible.
  • Monitor vendor advisories for updated fixed versions and backports.

Detection

  • Audit Kylin logs for DiagnosisService requests containing shell metacharacters or unexpected project names.
  • Alert on child processes spawned by the Kylin JVM (e.g., sh, bash, curl, wget) that are not part of normal operation.
  • Monitor outbound network connections from Kylin hosts for signs of post-exploitation activity.
  • Review access logs for unauthenticated requests to diagnosis or project-related endpoints from unusual sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-45456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-1956Apache Kylin REST API OS command injectionApache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated…KEVEPSS 97%analysed9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2022-24697Apache Kylin cube designer OS command injection via config overrideApache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the va…EPSS 85%analysed9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%9.8CVE-2020-13926Apache kylin sql injection vulnerabilityKylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2021-45456), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.