-
CVSS Score
-The vulnerability stems from insecure handling of host parameters in diag API endpoints. The patch modifies decodeHost() and encodeHost() methods to add AES encryption, indicating these were the vulnerable functions that processed untrusted host values using only Base64 encoding/decoding. These functions would appear in runtime traces when processing SSRF payloads as they directly handle the vulnerable parameter parsing and request forging logic.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.kylin:kylin-common-server | maven | >= 5.0.0, < 5.0.2 | 5.0.2 |
Ongoing coverage of React2Shell