漏洞描述
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.sonarsource.comhttps://www.sonarsource.com/blog/apache-kylin-command-injection-vulnerability/↗community.sonarsource.comhttps://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-1956↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2020/07/14/1↗lists.apache.orghttps://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf@%3Ccommits.kylin.apache.org%3E↗