Severity
High
Analysis Summary
CVE-2023-29055
Apache Kylin could allow a remote attacker to obtain sensitive information, caused by an insufficiently protected credentials in config file. By sniffing the network when kylin service runs over HTTP protocl, an attacker could exploit this vulnerability to obtain credentials information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-29055
Affected Vendors
Apache
Affected Products
- Apache Kylin 4.0.3
- Apache Kylin 2.0.0
Remediation
Upgrade to the latest version of Apache Kylin, available from the Apache Website.