VYPR
High severity8.8NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026

CVE-2020-1937

CVE-2020-1937

Description

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.kylin:kylin-server-baseMaven
< 2.6.52.6.5
org.apache.kylin:kylin-server-baseMaven
>= 3.0.0, < 3.0.13.0.1

Affected products

7
  • Apache/Kylin5 versions
    cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*range: >=2.3.0,<=2.3.2
    • cpe:2.3:a:apache:kylin:3.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:apache:kylin:3.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:apache:kylin:3.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:kylin:3.0.0:beta:*:*:*:*:*:*
  • Apache/Apache Kylinv5
    Range: ApacheKylin 2.3.0 to 2.3.2

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.