CVE-2020-1937
24.02.2020, 21:15
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
Vendor | Product | Version |
---|---|---|
apache | kylin | 2.3.0 ≤ 𝑥 ≤ 2.3.2 |
apache | kylin | 2.4.0 ≤ 𝑥 ≤ 2.4.1 |
apache | kylin | 2.5.0 ≤ 𝑥 ≤ 2.5.2 |
apache | kylin | 2.6.0 ≤ 𝑥 ≤ 2.6.4 |
apache | kylin | 3.0.0 |
apache | kylin | 3.0.0:alpha |
apache | kylin | 3.0.0:alpha2 |
apache | kylin | 3.0.0:beta |
𝑥
= Vulnerable software versions
References