{"id":"CVE-2020-1956","details":"Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.","aliases":["GHSA-gprm-xqrc-c2j3"],"modified":"2026-07-08T23:34:48.284723Z","published":"2020-05-22T14:15:11.840Z","references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06addec6297f0320f5111d%40%3Cuser.kylin.apache.org%3E"},{"type":"ADVISORY","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1956"},{"type":"FIX","url":"https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache.org%3E"},{"type":"FIX","url":"https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache.org%3E"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2020/07/14/1"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cannounce.apache.org%3E"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cdev.kylin.apache.org%3E"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cuser.kylin.apache.org%3E"},{"type":"EVIDENCE","url":"https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/kylin","events":[{"introduced":"1179ee72d0a2a2c629a649751ef43ae9e82dc87a"},{"last_affected":"8247ffc2d8a8a20381575389ffb3834d784ad4ce"},{"introduced":"158f8768debe99746c66e516e4596707a476d7d6"},{"last_affected":"0e519d859e217fbfadd534313376e532d2c647fa"},{"introduced":"8737bc1f555a2789a67462c8f8420b6ab3be97ce"},{"last_affected":"73d42edec5f6492b3d3ffc222c26dce4bdfe7263"},{"introduced":"b450cc52f976ddafba7c6625d2440670af94332b"},{"last_affected":"818c21cc9c2a995a58d85497a8649ebcf11a975c"}],"database_specific":{"extracted_events":[{"introduced":"2.3.0"},{"last_affected":"2.3.2"},{"introduced":"2.5.0"},{"last_affected":"2.5.2"},{"introduced":"2.6.0"},{"last_affected":"2.6.5"},{"introduced":"2.4.0"},{"last_affected":"2.4.0"},{"introduced":"2.4.1"},{"last_affected":"2.4.1"},{"introduced":"3.0.0-NA"},{"last_affected":"3.0.0-NA"},{"introduced":"3.0.0-alpha"},{"last_affected":"3.0.0-alpha"},{"introduced":"3.0.0-alpha2"},{"last_affected":"3.0.0-alpha2"},{"introduced":"3.0.0-beta"},{"last_affected":"3.0.0-beta"},{"introduced":"3.0.1"},{"last_affected":"3.0.1"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:apache:kylin:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:3.0.0:-:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:3.0.0:alpha:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:3.0.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:3.0.0:beta:*:*:*:*:*:*","cpe:2.3:a:apache:kylin:3.0.1:*:*:*:*:*:*:*"]}}],"versions":["2.4.0","2.4.1","3.0.0-NA","3.0.0-alpha","3.0.0-alpha2","3.0.0-beta","3.0.1","kylin-2.6.5","kylin-2.6.0","kylin-2.3.2","kylin-2.3.1","kylin-2.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1956.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}