← Vulnerability feed

Vulnerability record · CVE-2023-29055 · published 29 January 2024

CVE-2023-29055: Apache kylin insufficiently protected credentials vulnerability

Apache · Kylin

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers to hijack the HTTP payload and get access to the content of kylin.properties and potentially the containing credentials. To avoid this threat, users are recommended to  * Always turn on HTTPS so that network payload is encrypted. * Avoid putting credentials in kylin.properties, or at least not in plain text. * Use network firewalls to protect the serverside such that it is not accessible to external attackers. * Upgrade to version Apache Kylin 4.0.4, which filters out the sensitive content that goes to the Server Config web interface.

7.5 CVSS 3.1 High EPSS 1.1% · top 34.4% CWE-522 · Insufficiently protected credentials
7.5CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers to hijack the HTTP payload and get access to the content of kylin.properties and potentially the containing credentials. To avoid this threat, users are recommended to  * Always turn on HTTPS so that network payload is encrypted. * Avoid putting credentials in kylin.properties, or at least not in plain text. * Use network firewalls to protect the serverside such that it is not accessible to external attackers. * Upgrade to version Apache Kylin 4.0.4, which filters out the sensitive content that goes to the Server Config web interface.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-1956Apache Kylin REST API OS command injectionApache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated…KEVEPSS 97%analysed9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2022-24697Apache Kylin cube designer OS command injection via config overrideApache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the va…EPSS 85%analysed9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2021-45456Apache Kylin DiagnosisService project name check mismatch allows command injectionApache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell com…EPSS 89%analysed9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2023-29055), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.