← Back

CVE-2020-1956

Published: May 22, 2020Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Affected (10)

Products: Apache: Kylin
1 product
Kylin
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.3.0 to 2.3.2
From 2.5.0 to 2.5.2
From 2.6.0 to 2.6.5
Version 2.4.0
Version 2.4.1
Version 3.0.0
Version 3.0.0 alpha2
Version 3.0.0 alpha
Version 3.0.0 beta
Version 3.0.1

References (17)

Source: security@apache.org
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.