We found results for “”
CVE-2025-66518
Good to know:
Date: January 5, 2026
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
Severity Score
Severity Score
Weakness Type (CWE)
Path Traversal: 'dir/../../filename'
CWE-27Top Fix
Upgrade Version
Upgrade to version org.apache.kyuubi:kyuubi-server_2.12:1.10.3;https://github.com/apache/kyuubi.git - v1.10.3
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


