CVE-2025-61734
high · 7.5Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.
7.5
CVSS
19.8%
EPSS (exploit prob.)
97th
EPSS percentile
2025-10-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-552
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | kylin | >= 4.0.0, < 5.0.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-61734