Record summary

CVE-2020-1956 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2020-1956 in KEV.

Description

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 25, 2022 · CISA
VulnCheck KEV
Listed · Oct 14, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISA, CVE List2.3.0affected
<=2.6.5affected
<=3.0.1affected

org.apache.kylin:kylin-core-common

Browse Maven / org.apache.kylin:kylin-core-common
GitHub AdvisoryBefore 2.6.6 · Fixed in 2.6.6affected
3.0.0 to < 3.0.2 · Fixed in 3.0.2affected

Proofs of concept

1

Repository PoCs

GitHubb510/CVE-2020-1956Repository PoCby b510Stars: 0Not analyzed2 files

3.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHApache Kylin 3.0.1 - Command Injection VulnerabilityCVSS 8.8

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Impact

Successful exploitation of this vulnerability can lead to unauthorized remote code execution and potential compromise of the affected server.

Remediation

Upgrade to a patched version of Apache Kylin or apply the necessary security patches provided by the vendor.

WeaknessesCWE-78
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2020apachekylinrceoastkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-186961397
FOFA: icon_hash=-186961397

Source: ProjectDiscovery

References

Showing 12 of 18