Apache

Kylin

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.95%
  • Veröffentlicht 14.07.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:09

Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is pos...

  • EPSS 19.86%
  • Veröffentlicht 14.07.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:09

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibili...

Warnung Exploit
  • EPSS 97.34%
  • Veröffentlicht 22.05.2020 14:15:11
  • Zuletzt bearbeitet 23.10.2025 14:48:35

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

  • EPSS 2.67%
  • Veröffentlicht 24.02.2020 21:15:16
  • Zuletzt bearbeitet 21.11.2024 05:11:39

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.