Vulnerability record · CVE-2022-43396 · published 30 December 2022
CVE-2022-43396: Apache Kylin command injection via kylin.engine.spark-cmd blacklist bypass
Apache · Kylin
Apache Kylin's fix for CVE-2022-24697 relied on a blacklist to filter user-supplied commands, and that blacklist can be bypassed. An attacker who can control the kylin.engine.spark-cmd configuration parameter can inject arbitrary commands. Because the parameter feeds command execution, a bypass defeats the earlier patch and restores remote command execution risk.
Description
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low privileges, no user interaction and high EPSS makes this a serious post-authentication command injection, though it is not in KEV and no exploit code is confirmed in the record.
What it is
Apache Kylin's fix for CVE-2022-24697 relied on a blacklist to filter user-supplied commands, and that blacklist can be bypassed. An attacker who can control the kylin.engine.spark-cmd configuration parameter can inject arbitrary commands. Because the parameter feeds command execution, a bypass defeats the earlier patch and restores remote command execution risk.
Impact
An attacker gains arbitrary command execution with the privileges of the Kylin process, leading to full compromise of confidentiality, integrity and availability on the affected host.
Attack surface
Reached over the network through the Kylin interface that accepts the kylin.engine.spark-cmd configuration value; the CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.55 (99th percentile), and the vendor references are patch and advisory material only, so no public exploit code is confirmed in this record.
What to do
- Upgrade Apache Kylin to a release containing the corrected fix for CVE-2022-24697 and this bypass; consult the Apache mailing list advisory for the exact version.
- Restrict who can set or modify kylin.engine.spark-cmd and other engine configuration parameters to trusted administrators.
- Replace blacklist-based command filtering with strict allowlisting or parameterized command construction for Spark command execution.
- Run Kylin with least privilege and isolate it from sensitive hosts and credentials to limit the blast radius of command execution.
Detection
- Monitor Kylin configuration changes, especially writes to kylin.engine.spark-cmd, and alert on unexpected or shell-metacharacter-containing values.
- Audit process creation on Kylin hosts for child processes spawned by the Kylin service that do not match normal Spark job patterns.
- Review Kylin application logs for command execution errors or unusual command strings tied to configuration updates.
- Correlate configuration-change events with subsequent outbound network connections or file writes from the Kylin process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread/ob2ks04zl5ms0r44cd74y1xdl1rzfd1r | Mailing ListPatchVendor Advisory |
| https://lists.apache.org/thread/ob2ks04zl5ms0r44cd74y1xdl1rzfd1r | Mailing ListPatchVendor Advisory |
Track CVE-2022-43396 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-43396), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.