Severity: moderate 

Affected versions:

- Apache Kyuubi (org.apache.kyuubi:kyuubi-common) 1.7.0 through 1.11.1

Description:

Apache Kyuubi REST batch multipart upload handling uses the client-supplied 
multipart filename when creating a temporary uploaded resource. A remote 
attacker who can access the REST batch upload endpoint can provide path 
traversal sequences in the filename and cause the Kyuubi server process to 
write controlled content outside the intended upload directory, subject to 
filesystem permissions.


This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1.

Users are recommended to upgrade to version 1.12.0, which fixes the issue.

Credit:

LTSHFWJT (finder)

References:

https://kyuubi.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-52680

Reply via email to