CVE-2020-13925: OS Command Injection
Published Jul 14, 2020
·Updated
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely. Users of all previous versions after 2.3 should upgrade to 3.1.0.
Affected Software
1 affected component
Apache kylin>=2.3.0<3.1.0
Event History
Jul 14, 2020
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-13925?
CVE-2020-13925 is a vulnerability in Apache Kylin that allows remote execution of OS commands.
2
How severe is CVE-2020-13925?
CVE-2020-13925 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2020-13925?
Versions between 2.3.0 and 3.1.0 of Apache Kylin are affected by CVE-2020-13925.
4
What is the CWE ID for CVE-2020-13925?
The CWE IDs for CVE-2020-13925 are 20 and 78.
5
How can I fix CVE-2020-13925?
To fix CVE-2020-13925, users should update Apache Kylin to a version higher than 3.1.0.