High severity8.8NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026
CVE-2020-1937
CVE-2020-1937
Description
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.kylin:kylin-server-baseMaven | < 2.6.5 | 2.6.5 |
org.apache.kylin:kylin-server-baseMaven | >= 3.0.0, < 3.0.1 | 3.0.1 |
Affected products
7cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.2
- cpe:2.3:a:apache:kylin:3.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:apache:kylin:3.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:apache:kylin:3.0.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:apache:kylin:3.0.0:beta:*:*:*:*:*:*
- Apache/Apache Kylinv5Range: ApacheKylin 2.3.0 to 2.3.2
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-7hmh-8gwv-mfvqghsaADVISORY
- lists.apache.org/thread.html/rc574fef23740522f62ab3bbda4f6171be98aa7a25f3f54be143a80a8%40%3Cuser.kylin.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-1937ghsaADVISORY
- github.com/apache/kylin/commit/e373c64c96a54a7abfe4bccb82e8feb60db04749ghsaWEB
- lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf@%3Ccommits.kylin.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0@%3Ccommits.kylin.apache.org%3EghsaWEB
- snyk.io/vuln/SNYK-JAVA-ORGAPACHEKYLIN-552148ghsaWEB
- lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache.org%3Envd
- lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache.org%3Envd
News mentions
0No linked articles in our index yet.