CVE-2020-13921 | Apache SkyWalking SQL×¢Èë·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-06

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-13921

ʱ    ¼ä

2020-08-06

Àà   ÐÍ

SQL

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖØÒªÓÃÓÚ΢·þÎñ¡¢ÔÆÔ­ÉúºÍ»ùÓÚÈÝÆ÷µÈ»·¾³µÄÀûÓ÷¨Ê½»úÄܼලÆ÷¡£

2020Äê8ÔÂ5ÈÕ£¬Apache¹Ù·½°ä²¼²¼¸æ£¬½¨¸´ÁËÒ»¸öApache SkyWalking SQL×¢Èë·ì϶£¨CVE-2020-13921£©¡£¸Ã·ì϶ԴÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ´æÔÚSQL×¢Èë·ì϶£¬¹¥»÷ÕßʹÓÃĬÈÏÊ¢¿ªµÄδÊÚȨGraphQL½Ó¿Ú£¬»ú¹Ø¶ñÒâµÄÒªÇó°ü½øÐÐSQL×¢È룬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶¡£


0x02 ´ëÖý¨Òé


Apache¹Ù·½ÒѾ­°ä²¼·ì϶½¨¸´°æ±¾Apache SkyWalking 8.1.0£¬ÏÂÔØµØÖ·£º

http://skywalking.apache.org/downloads/


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13921


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E


0x05 ¹¦·òÏß


2020-08-05 Apache¹Ù·½°ä²¼²¼¸æ

2020-08-06 VSRC°ä²¼·ì϶¹«¸æ



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾