CVE-2020-13937 | Apache KylinÐÅϢй¶·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-200x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-13937 | ʱ ¼ä | 2020-10-20 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
Apache KylinÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£ÆäÖØÒªÌṩHadoop/SparkÖ®ÉϵÄSQL²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜÒÔÖ§³Ö³¬´ó¹æÄ£µÄÊý¾Ý²éÎÊ¡£
0x01 ·ì϶ÏêÇé

2020Äê10ÔÂ19ÈÕ£¬Apache Kylin°ä²¼°²È«¹«¸æ£¬KylinÖдæÔÚÒ»¸öδ¾Éí·ÝÑéÖ¤µÄÅäÏàÐÅϢй¶·ì϶£¬·ì϶¸ú×ÙΪCVE-2020-13937¡£¸Ã·ì϶ÊÇÓÉÓÚKylinʹÓõľ²Ì¬API´æÔÚ°²È«·ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÎÞÐèÈκÎÉí·ÝÑéÖ¤¾ÍÄܹ»Â¶³öKylinµÄÅäÏàÐÅÏ¢¡£
·ì϶ӰÏìÁìÓò£º
Kylin2.0.0¡¢2.1.0¡¢2.2.0¡¢2.3.0¡¢2.3.1¡¢2.3.2¡¢2.4.0¡¢2.4.1¡¢2.5.0¡¢2.5.1¡¢2.5.2¡¢2.6.0¡¢2.6.1£¬2.6.2£¬2.6.3£¬2.6.4£¬2.6.5£¬2.6.6
Kylin3.0.0-alpha¡¢3.0.0-alpha2¡¢3.0.0-beta¡¢3.0.0¡¢3.0.1¡¢3.0.2¡¢3.1.0
Kylin4.0.0-alpha
0x02 ´ëÖý¨Òé
ĿǰApache KylinÍŶÓÒѰ䲼а汾£¬½¨ÒéʵʱÉý¼¶µ½3.1.1¡£
ÏÂÔØµØÖ·£º
http://kylin.apache.org/cn/download/
һʱ´ëÊ©
ÈôÊDz»ÏëÉý¼¶ÖÁ3.1.1£¬Äܹ»±à×ë
"$KYLIN_HOME/WEB-INF/classes/kylinSecurity.xml"Îļþ£¬¶øºóɾ³ý´ËÐкó³ÁÆôkylinʹÆäÉúЧ£º
"<scr:intercept-url pattern="/api/admin/config" access="permitAll"/>".
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/dev@kylin.apache.org/msg12170.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13937
https://nvd.nist.gov/vuln/detail/CVE-2020-13937
0x04 ¹¦·òÏß
2020-10-19 Apache Kylin°ä²¼°²È«²¼¸æ
2020-10-20 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ