CVE-2020-13926

CVE-2020-13926

Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0.

Source: CVE-2020-13926

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다