CVE-2020-13921 | Apache SkyWalking SQL×¢ÈëÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-06

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-13921

ʱ    ¼ä

2020-08-06

Àà   ÐÍ

SQL

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1


0x01 Îó²îÏêÇé


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖ÷ÒªÓÃÓÚ΢·þÎñ¡¢ÔÆÔ­ÉúºÍ»ùÓÚÈÝÆ÷µÈÇéÐεÄÓ¦ÓóÌÐòÐÔÄܼàÊÓÆ÷¡£

2020Äê8ÔÂ5ÈÕ£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬ÐÞ¸´ÁËÒ»¸öApache SkyWalking SQL×¢ÈëÎó²î£¨CVE-2020-13921£©¡£¸ÃÎó²îÔ´ÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ±£´æSQL×¢ÈëÎó²î£¬¹¥»÷ÕßʹÓÃĬÈÏ¿ª·ÅµÄδÊÚȨGraphQL½Ó¿Ú£¬½á¹¹¶ñÒâµÄÇëÇó°ü¾ÙÐÐSQL×¢È룬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶¡£


0x02 ´¦Öóͷ£½¨Òé


Apache¹Ù·½ÒѾ­Ðû²¼Îó²îÐÞ¸´°æ±¾Apache SkyWalking 8.1.0£¬ÏÂÔØµØµã£º

http://skywalking.apache.org/downloads/


0x03 Ïà¹ØÐÂÎÅ


https://www.tenable.com/cve/CVE-2020-13921


0x04 ²Î¿¼Á´½Ó


https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E


0x05 ʱ¼äÏß


2020-08-05 Apache¹Ù·½Ðû²¼Í¨¸æ

2020-08-06 VSRCÐû²¼Îó²îͨ¸æ



×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!