CVE-2020-13921 | Apache SkyWalking SQL×¢ÈëÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-06

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-13921

ʱ    ¼ä

2020-08-06

Àà   ÐÍ

SQL

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖ÷ÒªÓÃÓÚ΢ЧÀÍ¡¢ÔÆÔ­ÉúºÍ»ùÓÚÈÝÆ÷µÈÇéÐεÄÓ¦ÓóÌÐòÐÔÄܼàÊÓÆ÷ ¡£¡£¡£¡£¡£¡£¡£

2020Äê8ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache SkyWalking SQL×¢ÈëÎó²î£¨CVE-2020-13921£© ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃĬÈÏ¿ª·ÅµÄδÊÚȨGraphQL½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬½á¹¹¶ñÒâµÄÇëÇó°ü¾ÙÐÐSQL×¢È룬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


Apache¹Ù·½ÒѾ­Ðû²¼Îó²îÐÞ¸´°æ±¾Apache SkyWalking 8.1.0£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£º

http://skywalking.apache.org/downloads/


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13921


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E


0x05 ʱ¼äÏß


2020-08-05 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-06 VSRCÐû²¼Îó²îͨ¸æ



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨