PT-2020-13785 · Apache · Apache Kylin

Published

2020-07-14

·

Updated

2020-07-27

·

CVE-2020-13926

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Kylin versions 2.0 through 3.0
Description The issue allows for SQL injection attacks due to the concatenation and execution of Hive SQL in Hive CLI or beeline when building a new segment. Some parts of the HQL are from system configurations, which can be overwritten by certain REST API, making the SQL injection attack possible.
Recommendations For Apache Kylin versions 2.0 through 3.0, upgrade to version 3.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the REST API that can overwrite system configurations to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13926
GHSA-HX5G-8HQ2-8X4W

Affected Products

Apache Kylin