← Vulnerability feed

Vulnerability record · CVE-2022-43396 · published 30 December 2022

CVE-2022-43396: Apache Kylin command injection via kylin.engine.spark-cmd blacklist bypass

Apache · Kylin

Apache Kylin's fix for CVE-2022-24697 relied on a blacklist to filter user-supplied commands, and that blacklist can be bypassed. An attacker who can control the kylin.engine.spark-cmd configuration parameter can inject arbitrary commands. Because the parameter feeds command execution, a bypass defeats the earlier patch and restores remote command execution risk.

8.8 CVSS 3.1 High EPSS 55% · top 1.0% CWE-184 · CWE-184
8.8CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with low privileges, no user interaction and high EPSS makes this a serious post-authentication command injection, though it is not in KEV and no exploit code is confirmed in the record.

What it is

Apache Kylin's fix for CVE-2022-24697 relied on a blacklist to filter user-supplied commands, and that blacklist can be bypassed. An attacker who can control the kylin.engine.spark-cmd configuration parameter can inject arbitrary commands. Because the parameter feeds command execution, a bypass defeats the earlier patch and restores remote command execution risk.

Impact

An attacker gains arbitrary command execution with the privileges of the Kylin process, leading to full compromise of confidentiality, integrity and availability on the affected host.

Attack surface

Reached over the network through the Kylin interface that accepts the kylin.engine.spark-cmd configuration value; the CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.55 (99th percentile), and the vendor references are patch and advisory material only, so no public exploit code is confirmed in this record.

What to do

  • Upgrade Apache Kylin to a release containing the corrected fix for CVE-2022-24697 and this bypass; consult the Apache mailing list advisory for the exact version.
  • Restrict who can set or modify kylin.engine.spark-cmd and other engine configuration parameters to trusted administrators.
  • Replace blacklist-based command filtering with strict allowlisting or parameterized command construction for Spark command execution.
  • Run Kylin with least privilege and isolate it from sensitive hosts and credentials to limit the blast radius of command execution.

Detection

  • Monitor Kylin configuration changes, especially writes to kylin.engine.spark-cmd, and alert on unexpected or shell-metacharacter-containing values.
  • Audit process creation on Kylin hosts for child processes spawned by the Kylin service that do not match normal Spark job patterns.
  • Review Kylin application logs for command execution errors or unusual command strings tied to configuration updates.
  • Correlate configuration-change events with subsequent outbound network connections or file writes from the Kylin process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43396 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-1956Apache Kylin REST API OS command injectionApache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated…KEVEPSS 97%analysed9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2022-24697Apache Kylin cube designer OS command injection via config overrideApache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the va…EPSS 85%analysed9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2021-45456Apache Kylin DiagnosisService project name check mismatch allows command injectionApache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell com…EPSS 89%analysed9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2022-43396), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.