CVE-2020-1956 | Apache KylinÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-29

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-1956

ʱ    ¼ä

2020-05-29

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Kylin 2.3.0 to 2.3.2

Kylin 2.4.0 to 2.4.1

Kylin 2.5.0 to 2.5.2

Kylin 2.6.0 to 2.6.5

Kylin 3.0.0-alpha, Kylin 3.0.0-alpha2, Kylin 3.0.0-beta, Kylin 3.0.0, Kylin 3.0.1


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Apache KylinÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£¸Ã²úÆ·ÖØÒªÌṩHadoop/SparkÖ®ÉϵÄSQL²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜ¡£

½üÈÕApache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache KylinÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1956£©¡£KylinÖеÄrestful API´æÔÚ°²È«·ì϶£¬Äܹ»½«osºÅÁîÓëÓû§ÊäÈë×Ö·û´®ÏÎ½ÓÆðÀ´£¬¹¥»÷ÕßÄܹ»ÔÚKylinûÓÐÈκα£»¤»òÑéÖ¤µÄÇé¿öÏÂÖ´ÐÐÈκÎosºÅÁî¡£

0x02 ´ëÖý¨Òé

¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½2.6.6»ò3.0.2°æ±¾£¬ÏÂÔØÁ´½Ó£º

http://kylin.apache.org/cn/download/

һʱ´ëÊ©£ºÓÉÓڸ÷ì϶µÄÈë¿ÚΪmigrateCube£¬¿É½«kylin.tool.auto-migrate-cube.enabledÉèÖÃΪfalseÒÔ½ûÓúÅÁîÖ´ÐС£


0x03 ÓйØÐÂÎÅ


https://osint.geekcq.com/2020/05/22/cve-2020-1956/


0x04 ²Î¿¼Á´½Ó


https://kylin.apache.org/docs/security.html

https://github.com/apache/kylin/commit/9cc3793ab2f2f0053c467a9b3f38cb7791cd436a#


0x05 ¹¦·òÏß


2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾