CVE-2020-1956
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Kylin OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-78
מוצרים מושפעים
apache: kylin
קישורים
- https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06adde… Mailing ListMitigationVendor Advisory
- https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06adde… Mailing ListMitigationVendor Advisory
- https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086… Mailing ListPatch
- https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b56941448… Mailing ListPatch
- https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086… Mailing ListPatch
- https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b56941448… Mailing ListPatch
- https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulne… ExploitThird Party Advisory
- https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulne… ExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/07/14/1 Mailing List
- https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab… Mailing List