CVE-2020-13921 | Apache SkyWalking SQL×¢Èë·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-08-060x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-13921 |
ʱ ¼ä |
2020-08-06 |
|
Àà ÐÍ |
SQL |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1 |
0x01 ·ì϶ÏêÇé
Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖØÒªÓÃÓÚ΢·þÎñ¡¢ÔÆÔÉúºÍ»ùÓÚÈÝÆ÷µÈ»·¾³µÄÀûÓ÷¨Ê½»úÄܼලÆ÷¡£
2020Äê8ÔÂ5ÈÕ£¬Apache¹Ù·½°ä²¼²¼¸æ£¬½¨¸´ÁËÒ»¸öApache SkyWalking SQL×¢Èë·ì϶£¨CVE-2020-13921£©¡£¸Ã·ì϶ԴÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ´æÔÚSQL×¢Èë·ì϶£¬¹¥»÷ÕßʹÓÃĬÈÏÊ¢¿ªµÄδÊÚȨGraphQL½Ó¿Ú£¬»ú¹Ø¶ñÒâµÄÒªÇó°ü½øÐÐSQL×¢È룬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶¡£
0x02 ´ëÖý¨Òé
Apache¹Ù·½ÒѾ°ä²¼·ì϶½¨¸´°æ±¾Apache SkyWalking 8.1.0£¬ÏÂÔØµØÖ·£º
http://skywalking.apache.org/downloads/
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13921
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E
0x05 ¹¦·òÏß
2020-08-05 Apache¹Ù·½°ä²¼²¼¸æ
2020-08-06 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ