oss-sec mailing list archives

CVE-2024-23590: Apache Kylin: Session fixation in web interface


From: Li Yang <liyang () apache org>
Date: Sun, 03 Nov 2024 05:46:42 +0000

Severity: low

Affected versions:

- Apache Kylin 2.0.0 before 5.0.0

Description:

Session Fixation vulnerability in Apache Kylin.

This issue affects Apache Kylin: from 2.0.0 through 4.x.

Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.

Credit:

XJB Security Team (reporter)

References:

https://kylin.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-23590


Current thread: