CVE-2020-13921 | Apache SkyWalking SQL×¢ÈëÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-08-060x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-13921 |
ʱ ¼ä |
2020-08-06 |
Àà ÐÍ |
SQL |
µÈ ¼¶ |
¸ßΣ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1 |
0x01 Îó²îÏêÇé
Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖ÷ÒªÓÃÓÚ΢ЧÀÍ¡¢ÔÆÔÉúºÍ»ùÓÚÈÝÆ÷µÈÇéÐεÄÓ¦ÓóÌÐòÐÔÄܼàÊÓÆ÷¡£¡£¡£¡£¡£¡£¡£
2020Äê8ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache SkyWalking SQL×¢ÈëÎó²î£¨CVE-2020-13921£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃĬÈÏ¿ª·ÅµÄδÊÚȨGraphQL½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬½á¹¹¶ñÒâµÄÇëÇó°ü¾ÙÐÐSQL×¢È룬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Apache¹Ù·½ÒѾÐû²¼Îó²îÐÞ¸´°æ±¾Apache SkyWalking 8.1.0£¬£¬£¬£¬£¬£¬£¬ÏÂÔØµØµã£º
http://skywalking.apache.org/downloads/
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13921
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E
0x05 ʱ¼äÏß
2020-08-05 Apache¹Ù·½Ðû²¼Í¨¸æ
2020-08-06 VSRCÐû²¼Îó²îͨ¸æ
