CVE-2022-24697 | Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.
Conclusion & alert: CVE-2022-24697 is rated High Risk (79.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 84.78%, 100th percentile).Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +71.18% over the last day, indicating growing attacker interest.Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2022-24697
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).