CVE-2020-13937 | Apache KylinÐÅϢй¶Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-10-200x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-13937 | ʱ ¼ä | 2020-10-20 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
Apache KylinÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÂþÑÜʽÆÊÎöÐÍÊý¾Ý¿ÍÕ»¡£¡£¡£¡£ÆäÖ÷ÒªÌṩHadoop/SparkÖ®ÉϵÄSQLÅÌÎʽӿڼ°¶àάÆÊÎö£¨OLAP£©µÈ¹¦Ð§ÒÔÖ§³Ö³¬´ó¹æÄ£µÄÊý¾ÝÅÌÎÊ¡£¡£¡£¡£
0x01 Îó²îÏêÇé
2020Äê10ÔÂ19ÈÕ£¬£¬£¬£¬Apache KylinÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬KylinÖб£´æÒ»¸öδ¾Éí·ÝÑéÖ¤µÄÉèÖÃÐÅϢй¶Îó²î£¬£¬£¬£¬Îó²î¸ú×ÙΪCVE-2020-13937¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚKylinʹÓõľ²Ì¬API±£´æÇå¾²Îó²î£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÎÞÐèÈκÎÉí·ÝÑéÖ¤¾Í¿ÉÒÔ̻¶KylinµÄÉèÖÃÐÅÏ¢¡£¡£¡£¡£
Îó²îÓ°Ïì¹æÄ££º
Kylin2.0.0¡¢2.1.0¡¢2.2.0¡¢2.3.0¡¢2.3.1¡¢2.3.2¡¢2.4.0¡¢2.4.1¡¢2.5.0¡¢2.5.1¡¢2.5.2¡¢2.6.0¡¢2.6.1£¬£¬£¬£¬2.6.2£¬£¬£¬£¬2.6.3£¬£¬£¬£¬2.6.4£¬£¬£¬£¬2.6.5£¬£¬£¬£¬2.6.6
Kylin3.0.0-alpha¡¢3.0.0-alpha2¡¢3.0.0-beta¡¢3.0.0¡¢3.0.1¡¢3.0.2¡¢3.1.0
Kylin4.0.0-alpha
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚApache KylinÍŶÓÒÑÐû²¼Ð°汾£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½3.1.1¡£¡£¡£¡£
ÏÂÔØµØµã£º
http://kylin.apache.org/cn/download/
ÔÝʱ²½·¥
ÈôÊDz»ÏëÉý¼¶ÖÁ3.1.1£¬£¬£¬£¬¿ÉÒÔ±à¼
"$KYLIN_HOME/WEB-INF/classes/kylinSecurity.xml"Îļþ£¬£¬£¬£¬È»ºóɾ³ý´ËÐкóÖØÆôkylinʹÆäÉúЧ£º
"<scr:intercept-url pattern="/api/admin/config" access="permitAll"/>".
0x03 ²Î¿¼Á´½Ó
https://www.mail-archive.com/dev@kylin.apache.org/msg12170.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13937
https://nvd.nist.gov/vuln/detail/CVE-2020-13937
0x04 ʱ¼äÏß
2020-10-19 Apache KylinÐû²¼Ç徲ͨ¸æ
2020-10-20 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/