Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-1937
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.101
EPSS Ranking
92.7%
CVSS Severity
CVSS v3 Score
8.8
CVSS v2 Score
6.5
References
https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache.org%3E
https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache.org%3E
https://lists.apache.org/thread.html/rc574fef23740522f62ab3bbda4f6171be98aa7a25f3f54be143a80a8%40%3Cuser.kylin.apache.org%3E
https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache.org%3E
https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache.org%3E
https://lists.apache.org/thread.html/rc574fef23740522f62ab3bbda4f6171be98aa7a25f3f54be143a80a8%40%3Cuser.kylin.apache.org%3E
Products affected by CVE-2020-1937
Apache
»
Kylin
»
Version:
2.3.0
cpe:2.3:a:apache:kylin:2.3.0
Apache
»
Kylin
»
Version:
2.3.1
cpe:2.3:a:apache:kylin:2.3.1
Apache
»
Kylin
»
Version:
2.3.2
cpe:2.3:a:apache:kylin:2.3.2
Apache
»
Kylin
»
Version:
2.4.0
cpe:2.3:a:apache:kylin:2.4.0
Apache
»
Kylin
»
Version:
2.4.1
cpe:2.3:a:apache:kylin:2.4.1
Apache
»
Kylin
»
Version:
2.5.0
cpe:2.3:a:apache:kylin:2.5.0
Apache
»
Kylin
»
Version:
2.5.1
cpe:2.3:a:apache:kylin:2.5.1
Apache
»
Kylin
»
Version:
2.5.2
cpe:2.3:a:apache:kylin:2.5.2
Apache
»
Kylin
»
Version:
2.6.0
cpe:2.3:a:apache:kylin:2.6.0
Apache
»
Kylin
»
Version:
2.6.1
cpe:2.3:a:apache:kylin:2.6.1
Apache
»
Kylin
»
Version:
2.6.2
cpe:2.3:a:apache:kylin:2.6.2
Apache
»
Kylin
»
Version:
2.6.3
cpe:2.3:a:apache:kylin:2.6.3
Apache
»
Kylin
»
Version:
2.6.4
cpe:2.3:a:apache:kylin:2.6.4
Apache
»
Kylin
»
Version:
3.0.0
cpe:2.3:a:apache:kylin:3.0.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved