PT-2020-13785 · Apache · Apache Kylin
Published
2020-07-14
·
Updated
2020-07-27
·
CVE-2020-13926
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Kylin versions 2.0 through 3.0
Description
The issue allows for SQL injection attacks due to the concatenation and execution of Hive SQL in Hive CLI or beeline when building a new segment. Some parts of the HQL are from system configurations, which can be overwritten by certain REST API, making the SQL injection attack possible.
Recommendations
For Apache Kylin versions 2.0 through 3.0, upgrade to version 3.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the REST API that can overwrite system configurations to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Kylin