VulnerabilityModified
CVE-2025-61734
Files or Directories Accessible to External Parties vulnerability in Apache Kylin.
HIGH 7.5EPSS 19.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 19.78% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- apache/kylin
- Source
- security@apache.org
References
- https://lists.apache.org/thread/z705g7sn3g0bkchlqbo1hz1tyqorn4d2Issue Tracking, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/09/30/8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.