VYPR
Critical severity9.8OSV Advisory· Published Aug 5, 2020· Updated Jun 17, 2026

CVE-2020-13921

CVE-2020-13921

Description

Resolved Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.skywalking:oap-serverMaven
< 8.1.08.1.0

Affected products

7
  • Apache/SkywalkingOSV6 versions
    1.0-alpha1, 1.0-alpha2, 1.0-beta, …+ 5 more
    • (no CPE)range: 1.0-alpha1, 1.0-alpha2, 1.0-beta, …
    • cpe:2.3:a:apache:skywalking:6.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:skywalking:6.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:skywalking:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:skywalking:8.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:skywalking:8.0.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.