CVE Database
/

CVE-2020-1937

Back to search

CVE-2020-1937

Published: Feb 24, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

VendorProductVersions

Apache

Apache Kylin

affected
ApacheKylin 2.3.0 to 2.3.2
affected
2.4.0 to 2.4.1
affected
2.5.0 to 2.5.2
affected
2.6.0 to 2.6.4
affected
3.0.0-alpha

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now