Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
https://github.com/b510/CVE-2020-1956
https://github.com/advisories/GHSA-gprm-xqrc-c2j3
https://github.com/advisories/GHSA-qwfw-gxx2-mmv2
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1956
https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706