CNNVD-202601-927 Information

CNNVD ID

CNNVD-202601-927

CVE-2025-66518

  • CNNVD Published: 2026-01-05

Description (Chinese)

Apache Kyuubi是Apache基金会的一个分布式SQL网关。 Apache Kyuubi 1.6.0版本至1.10.2版本存在安全漏洞,该漏洞源于客户端可绕过服务器端配置,可能导致访问未授权的本地文件。

Description (English)

Apache Kyuubi is a distributed SQL gateway to the Apache Foundation. There is a security gap between Appache Kyuubi Versions 1.6.0 to 1.10.2, which stems from client access to unauthorized local files that can bypass server-end configurations.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

阿帕奇

Published

2026-01-05

Last Modified

2026-02-24

References

https://lists.apache.org/thread/xp460bwbyzdhho34ljd4nchyt2fmhodl http://www.openwall.com/lists/oss-security/2026/01/05/1 https://access.redhat.com/security/cve/cve-2025-66518

Patch

https://kyuubi.apache.org/releases.html

Share on: