Lucene search

K
osvGoogleOSV:GHSA-GPRM-XQRC-C2J3
HistoryJul 27, 2020 - 10:51 p.m.

Command Injection in Kylin

2020-07-2722:51:44
Google
osv.dev
13

0.974 High

EPSS

Percentile

99.9%

Kylin has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

References