Количество 2
Количество 2
CVE-2020-13926
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0.
GHSA-hx5g-8hq2-8x4w
SQL Injection in Kylin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-13926 Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0. | CVSS3: 9.8 | 3% Низкий | больше 5 лет назад | |
GHSA-hx5g-8hq2-8x4w SQL Injection in Kylin | CVSS3: 9.8 | 3% Низкий | больше 5 лет назад |
Уязвимостей на страницу