CVE-2020-1956 | Apache KylinÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-29

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-1956

ʱ    ¼ä

2020-05-29

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Kylin 2.3.0 to 2.3.2

Kylin 2.4.0 to 2.4.1

Kylin 2.5.0 to 2.5.2

Kylin 2.6.0 to 2.6.5

Kylin 3.0.0-alpha, Kylin 3.0.0-alpha2, Kylin 3.0.0-beta, Kylin 3.0.0, Kylin 3.0.1


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



Apache KylinÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã²úÆ·ÖØÒªÌṩHadoop/SparkÖ®ÉϵÄSQL²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜ¡£¡£ ¡£¡£¡£¡£¡£¡£

½üÈÕApache¹Ù·½°ä²¼¹«¸æ£¬£¬£¬£¬£¬ £¬ £¬£¬½¨¸´ÁËÒ»¸öApache KylinÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1956£©¡£¡£ ¡£¡£¡£¡£¡£¡£KylinÖеÄrestful API´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬Äܹ»½«osºÅÁîÓëÓû§ÊäÈë×Ö·û´®ÏÎ½ÓÆðÀ´£¬£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷ÕßÄܹ»ÔÚKylinûÓÐÈκα£» £» £»£»£»£»£»£»¤»òÑéÖ¤µÄÇé¿öÏÂÖ´ÐÐÈκÎosºÅÁî¡£¡£ ¡£¡£¡£¡£¡£¡£

0x02 ´ëÖý¨Òé

¹Ù·½ÒѰ䲼×îа汾½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬ £¬ £¬£¬Óû§Ó¦¾¡¿ìÉý¼¶µ½2.6.6»ò3.0.2°æ±¾£¬£¬£¬£¬£¬ £¬ £¬£¬ÏÂÔØÁ´½Ó£º

http://kylin.apache.org/cn/download/

һʱ´ëÊ©£ºÓÉÓڸ÷ì϶µÄÈë¿ÚΪmigrateCube£¬£¬£¬£¬£¬ £¬ £¬£¬¿É½«kylin.tool.auto-migrate-cube.enabledÉèÖÃΪfalseÒÔ½ûÓúÅÁîÖ´ÐÓ×£¡£ ¡£¡£¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ


https://osint.geekcq.com/2020/05/22/cve-2020-1956/


0x04 ²Î¿¼Á´½Ó


https://kylin.apache.org/docs/security.html

https://github.com/apache/kylin/commit/9cc3793ab2f2f0053c467a9b3f38cb7791cd436a#


0x05 ¹¦·òÏß


2020-05-29 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website