CVE-2025-66518
🟡 Monitoruj
Obejście konfiguracji w Apache Kyuubi pozwala na dostęp do nieautoryzowanych plików lokalnych.
CVSS
8.8
EPSS
1.0%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.0% |
| Opublikowano (NVD) | 2026-01-05 09:15:54 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://lists.apache.org/thread/xp460bwbyzdhho34ljd4nchyt2fmhodl ([email protected]) [Mailing List]
- http://www.openwall.com/lists/oss-security/2026/01/05/1 (af854a3a-2127-422b-91ae-364da2661108) [Mailing List, Third Party Advisory]