← Back

CVE-2020-1937

nvd nist
Published: Feb 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

Affected (8)

Products: Apache: Kylin
1 product
Kylin
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.3.0 to 2.3.2
From 2.4.0 to 2.4.1
From 2.5.0 to 2.5.2
From 2.6.0 to 2.6.4
Version 3.0.0
Version 3.0.0 alpha2
Version 3.0.0 alpha
Version 3.0.0 beta

Timeline

No history available yet.