CVE-2020-1956
22.05.2020, 14:15
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
Vendor | Product | Version |
---|---|---|
apache | kylin | 2.3.0 ≤ 𝑥 ≤ 2.3.2 |
apache | kylin | 2.5.0 ≤ 𝑥 ≤ 2.5.2 |
apache | kylin | 2.6.0 ≤ 𝑥 ≤ 2.6.5 |
apache | kylin | 2.4.0 |
apache | kylin | 2.4.1 |
apache | kylin | 3.0.0 |
apache | kylin | 3.0.0:alpha |
apache | kylin | 3.0.0:alpha2 |
apache | kylin | 3.0.0:beta |
apache | kylin | 3.0.1 |
𝑥
= Vulnerable software versions
References