CVE-2020-1956 | Apache KylinÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-290x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-1956 |
ʱ ¼ä |
2020-05-29 |
|
Àà ÐÍ |
RCE |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Kylin 2.3.0 to 2.3.2 Kylin 2.4.0 to 2.4.1 Kylin 2.5.0 to 2.5.2 Kylin 2.6.0 to 2.6.5 Kylin 3.0.0-alpha, Kylin 3.0.0-alpha2, Kylin 3.0.0-beta, Kylin 3.0.0, Kylin 3.0.1 |
0x01 ·ì϶ÏêÇé
Apache KylinÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£¸Ã²úÆ·ÖØÒªÌṩHadoop/SparkÖ®ÉϵÄSQL²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜ¡£
½üÈÕApache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache KylinÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1956£©¡£KylinÖеÄrestful API´æÔÚ°²È«·ì϶£¬Äܹ»½«osºÅÁîÓëÓû§ÊäÈë×Ö·û´®ÏÎ½ÓÆðÀ´£¬¹¥»÷ÕßÄܹ»ÔÚKylinûÓÐÈκα£»¤»òÑéÖ¤µÄÇé¿öÏÂÖ´ÐÐÈκÎosºÅÁî¡£
0x02 ´ëÖý¨Òé
¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½2.6.6»ò3.0.2°æ±¾£¬ÏÂÔØÁ´½Ó£º
http://kylin.apache.org/cn/download/
һʱ´ëÊ©£ºÓÉÓڸ÷ì϶µÄÈë¿ÚΪmigrateCube£¬¿É½«kylin.tool.auto-migrate-cube.enabledÉèÖÃΪfalseÒÔ½ûÓúÅÁîÖ´ÐС£
0x03 ÓйØÐÂÎÅ
https://osint.geekcq.com/2020/05/22/cve-2020-1956/
0x04 ²Î¿¼Á´½Ó
https://kylin.apache.org/docs/security.html
https://github.com/apache/kylin/commit/9cc3793ab2f2f0053c467a9b3f38cb7791cd436a#
0x05 ¹¦·òÏß
2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ