Loading
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.
Use CWE-184, Apache vendor hub and Kylin product page to widen CVE-2022-43396 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-44621, CVE-2022-24697 and CVE-2024-23590 for nearby disclosures in the same product family.