CVE-2020-1956 | Apache KylinÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-29

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-1956

ʱ    ¼ä

2020-05-29

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Kylin 2.3.0 to 2.3.2

Kylin 2.4.0 to 2.4.1

Kylin 2.5.0 to 2.5.2

Kylin 2.6.0 to 2.6.5

Kylin 3.0.0-alpha, Kylin 3.0.0-alpha2, Kylin 3.0.0-beta, Kylin 3.0.0, Kylin 3.0.1


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Apache KylinÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÂþÑÜʽÆÊÎöÐÍÊý¾Ý¿ÍÕ»¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÌṩHadoop/SparkÖ®ÉϵÄSQLÅÌÎʽӿڼ°¶àάÆÊÎö£¨OLAP£©µÈ¹¦Ð§¡£¡£¡£

¿ËÈÕApache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache KylinÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-1956£©¡£¡£¡£KylinÖеÄrestful API±£´æÇå¾²Îó²î£¬£¬£¬¿ÉÒÔ½«osÏÂÁîÓëÓû§ÊäÈë×Ö·û¹´Í¨½ÓÆðÀ´£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚKylinûÓÐÈκα£»£»£»£»¤»òÑéÖ¤µÄÇéÐÎÏÂÖ´ÐÐÈκÎosÏÂÁî¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½2.6.6»ò3.0.2°æ±¾£¬£¬£¬ÏÂÔØÁ´½Ó£º

http://kylin.apache.org/cn/download/

ÔÝʱ²½·¥£ºÓÉÓÚ¸ÃÎó²îµÄÈë¿ÚΪmigrateCube£¬£¬£¬¿É½«kylin.tool.auto-migrate-cube.enabledÉèÖÃΪfalseÒÔ½ûÓÃÏÂÁîÖ´ÐС£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://osint.geekcq.com/2020/05/22/cve-2020-1956/


0x04 ²Î¿¼Á´½Ó


https://kylin.apache.org/docs/security.html

https://github.com/apache/kylin/commit/9cc3793ab2f2f0053c467a9b3f38cb7791cd436a#


0x05 ʱ¼äÏß


2020-05-29 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨