[MAVEN:GHSA-MGPF-HHGF-CXG4] In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin.

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

ID
MAVEN:GHSA-MGPF-HHGF-CXG4
Severity
high
URL
https://github.com/advisories/GHSA-mgpf-hhgf-cxg4
Published
2022-01-08T00:43:16
(2 years ago)
Modified
2023-01-27T05:01:59
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.kylin/kylin org.apache.kylin kylin = 4.0.0
Fixed pkg:maven/org.apache.kylin/kylin org.apache.kylin kylin = 4.0.1
Affected pkg:maven/org.apache.kylin/kylin org.apache.kylin kylin < 3.1.3
Fixed pkg:maven/org.apache.kylin/kylin org.apache.kylin kylin = 3.1.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...