PT-2026-66744 · Apache+1 · Apache Kyuubi+1
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Kyuubi versions 1.6.0 through 1.11.x
Description
Clients accessing the Apache Kyuubi Server through Kyuubi frontend protocols can bypass the server-side configuration
kyuubi.session.local.dir.allowlist by using unprefixed Spark config aliases.Recommendations
Upgrade to version 1.12.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kyuubi
Kyuubi