Apache

Kyuubi

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 31.07.2026 09:58:15
  • Zuletzt bearbeitet 10.08.2026 14:22:12

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affec...

  • EPSS 0.75%
  • Veröffentlicht 30.07.2026 16:17:14
  • Zuletzt bearbeitet 05.08.2026 17:22:23

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the fi...

  • EPSS 0.65%
  • Veröffentlicht 29.07.2026 09:07:18
  • Zuletzt bearbeitet 05.08.2026 18:36:12

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, re...

  • EPSS 0.91%
  • Veröffentlicht 05.01.2026 08:46:27
  • Zuletzt bearbeitet 07.10.2026 11:10:00

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 th...