GHSA-f8r6-6222-9pvc
HIGHCVE-2025-66518Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.
- Affected
- >= 1.6.0, < 1.10.3
- Fixed in
- 1.10.3
- Weakness
- CWE-22
- Published
- 2026-01-05
- Source
- github