CVE-2020-13937 | Apache KylinÐÅϢй¶·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-10-20

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-13937

ʱ   ¼ä

2020-10-20

Àà   ÐÍ

ÐÅϢй¶

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

Apache KylinÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£ÆäÖØÒªÌṩHadoop/SparkÖ®ÉϵÄSQL²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜÒÔÖ§³Ö³¬´ó¹æÄ£µÄÊý¾Ý²éÎÊ¡£


0x01 ·ì϶ÏêÇé

image.png

 

2020Äê10ÔÂ19ÈÕ£¬Apache Kylin°ä²¼°²È«¹«¸æ£¬KylinÖдæÔÚÒ»¸öδ¾­Éí·ÝÑéÖ¤µÄÅäÏàÐÅϢй¶·ì϶£¬·ì϶¸ú×ÙΪCVE-2020-13937¡£¸Ã·ì϶ÊÇÓÉÓÚKylinʹÓõľ²Ì¬API´æÔÚ°²È«·ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÎÞÐèÈκÎÉí·ÝÑéÖ¤¾ÍÄܹ»Â¶³öKylinµÄÅäÏàÐÅÏ¢¡£

 

·ì϶ӰÏìÁìÓò£º

Kylin2.0.0¡¢2.1.0¡¢2.2.0¡¢2.3.0¡¢2.3.1¡¢2.3.2¡¢2.4.0¡¢2.4.1¡¢2.5.0¡¢2.5.1¡¢2.5.2¡¢2.6.0¡¢2.6.1£¬2.6.2£¬2.6.3£¬2.6.4£¬2.6.5£¬2.6.6

Kylin3.0.0-alpha¡¢3.0.0-alpha2¡¢3.0.0-beta¡¢3.0.0¡¢3.0.1¡¢3.0.2¡¢3.1.0

Kylin4.0.0-alpha


0x02 ´ëÖý¨Òé

ĿǰApache KylinÍŶÓÒѰ䲼а汾£¬½¨ÒéʵʱÉý¼¶µ½3.1.1¡£

ÏÂÔØµØÖ·£º

http://kylin.apache.org/cn/download/

 

һʱ´ëÊ©

ÈôÊDz»ÏëÉý¼¶ÖÁ3.1.1£¬Äܹ»±à×ë

"$KYLIN_HOME/WEB-INF/classes/kylinSecurity.xml"Îļþ£¬¶øºóɾ³ý´ËÐкó³ÁÆôkylinʹÆäÉúЧ£º

"<scr:intercept-url pattern="/api/admin/config" access="permitAll"/>".

 

0x03 ²Î¿¼Á´½Ó

https://www.mail-archive.com/dev@kylin.apache.org/msg12170.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13937

https://nvd.nist.gov/vuln/detail/CVE-2020-13937


0x04 ¹¦·òÏß

2020-10-19  Apache Kylin°ä²¼°²È«²¼¸æ

2020-10-20  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


 image.png