CVE-2020-13937 | Apache KylinÐÅϢй¶Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-20

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-13937

ʱ   ¼ä

2020-10-20

Àà   ÐÍ

ÐÅϢй¶

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

Apache KylinÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÂþÑÜʽÆÊÎöÐÍÊý¾Ý¿ÍÕ»¡£¡£¡£¡£ÆäÖ÷ÒªÌṩHadoop/SparkÖ®ÉϵÄSQLÅÌÎʽӿڼ°¶àάÆÊÎö£¨OLAP£©µÈ¹¦Ð§ÒÔÖ§³Ö³¬´ó¹æÄ£µÄÊý¾ÝÅÌÎÊ¡£¡£¡£¡£


0x01 Îó²îÏêÇé

image.png

 

2020Äê10ÔÂ19ÈÕ£¬£¬£¬£¬Apache KylinÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬KylinÖб£´æÒ»¸öδ¾­Éí·ÝÑéÖ¤µÄÉèÖÃÐÅϢй¶Îó²î£¬£¬£¬£¬Îó²î¸ú×ÙΪCVE-2020-13937¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚKylinʹÓõľ²Ì¬API±£´æÇå¾²Îó²î£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÎÞÐèÈκÎÉí·ÝÑéÖ¤¾Í¿ÉÒÔ̻¶KylinµÄÉèÖÃÐÅÏ¢¡£¡£¡£¡£

 

Îó²îÓ°Ïì¹æÄ££º

Kylin2.0.0¡¢2.1.0¡¢2.2.0¡¢2.3.0¡¢2.3.1¡¢2.3.2¡¢2.4.0¡¢2.4.1¡¢2.5.0¡¢2.5.1¡¢2.5.2¡¢2.6.0¡¢2.6.1£¬£¬£¬£¬2.6.2£¬£¬£¬£¬2.6.3£¬£¬£¬£¬2.6.4£¬£¬£¬£¬2.6.5£¬£¬£¬£¬2.6.6

Kylin3.0.0-alpha¡¢3.0.0-alpha2¡¢3.0.0-beta¡¢3.0.0¡¢3.0.1¡¢3.0.2¡¢3.1.0

Kylin4.0.0-alpha


0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚApache KylinÍŶÓÒÑÐû²¼Ð°汾£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶µ½3.1.1¡£¡£¡£¡£

ÏÂÔØµØµã£º

http://kylin.apache.org/cn/download/

 

ÔÝʱ²½·¥

ÈôÊDz»ÏëÉý¼¶ÖÁ3.1.1£¬£¬£¬£¬¿ÉÒԱ༭

"$KYLIN_HOME/WEB-INF/classes/kylinSecurity.xml"Îļþ£¬£¬£¬£¬È»ºóɾ³ý´ËÐкóÖØÆôkylinʹÆäÉúЧ£º

"<scr:intercept-url pattern="/api/admin/config" access="permitAll"/>".

 

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/dev@kylin.apache.org/msg12170.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13937

https://nvd.nist.gov/vuln/detail/CVE-2020-13937


0x04 ʱ¼äÏß

2020-10-19  Apache KylinÐû²¼Ç徲ͨ¸æ

2020-10-20  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/


 image.png