oss-sec mailing list archives

CVE-2025-61735: Apache Kylin: Server-Side Request Forgery


From: Li Yang <liyang () apache org>
Date: Tue, 30 Sep 2025 15:48:03 +0000

Severity: low 

Affected versions:

- Apache Kylin 4.0.0 through 5.0.2

Description:

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin.

This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin 
access is well protected.

Users are recommended to upgrade to version 5.0.3, which fixes the issue.

This issue is being tracked as KYLIN-6082 

Credit:

liuhuajin <liuhuajin1 () huawei com> (finder)

References:

https://kylin.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-61735
https://issues.apache.org/jira/browse/KYLIN-6082


Current thread: