Vulnerability Description
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Kylin | >= 2.3.0, <= 2.3.2 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2020/07/14/1Mailing List
- https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulneraExploitThird Party Advisory
- https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b508656Mailing ListPatch
- https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06addec6Mailing ListMitigationVendor Advisory
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
- https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fMailing ListPatch
- http://www.openwall.com/lists/oss-security/2020/07/14/1Mailing List
- https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulneraExploitThird Party Advisory
- https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b508656Mailing ListPatch
- https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06addec6Mailing ListMitigationVendor Advisory
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab00Mailing List
FAQ
What is CVE-2020-1956?
CVE-2020-1956 is a vulnerability with a CVSS score of 8.8 (HIGH). Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without...
How severe is CVE-2020-1956?
CVE-2020-1956 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1956?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Kylin.