CVE-2020-13921 | Apache SkyWalking SQL×¢ÈëÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-08-060x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-13921 |
ʱ ¼ä |
2020-08-06 |
|
Àà ÐÍ |
SQL |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Apache SkyWalking 6.5.0¡¢6.6.0¡¢ 7.0.0¡¢ 8.0.0¡¢ 8.0.1 |
0x01 Îó²îÏêÇé
Apache SkyWalkingÊÇÃÀ¹ú°¢ÅÁÆæÈí¼þ£¨Apache Software£©»ù½ð»áµÄÒ»¿îÖ÷ÒªÓÃÓÚ΢ЧÀÍ¡¢ÔÆÔÉúºÍ»ùÓÚÈÝÆ÷µÈÇéÐεÄÓ¦ÓóÌÐòÐÔÄܼàÊÓÆ÷¡£¡£¡£¡£¡£¡£
2020Äê8ÔÂ5ÈÕ£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Í¨¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öApache SkyWalking SQL×¢ÈëÎó²î£¨CVE-2020-13921£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚApache SkyWalkingÖеÄH2/MySQL/TiDB´æ´¢ÊµÏÖ±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬¹¥»÷ÕßʹÓÃĬÈÏ¿ª·ÅµÄδÊÚȨGraphQL½Ó¿Ú£¬£¬£¬£¬½á¹¹¶ñÒâµÄÇëÇó°ü¾ÙÐÐSQL×¢È룬£¬£¬£¬´Ó¶øµ¼ÖÂÓû§Êý¾Ý¿âÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Apache¹Ù·½ÒѾÐû²¼Îó²îÐÞ¸´°æ±¾Apache SkyWalking 8.1.0£¬£¬£¬£¬ÏÂÔØµØµã£º
http://skywalking.apache.org/downloads/
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-13921
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E
0x05 ʱ¼äÏß
2020-08-05 Apache¹Ù·½Ðû²¼Í¨¸æ
2020-08-06 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ