« Volver al listado

CVE-2020-13921

Estado: ModificadaCrítica (9.8)—

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13921",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Apache SkyWalking",
          "versions": [
            {
              "status": "affected",
              "version": "Apache SkyWalking 6.5.0, 6.6.0, 7.0.0, 8.0.0, 8.0.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-05T14:15:12.327",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2020/08/05/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://github.com/apache/skywalking/pull/4970",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6%40%3Cdev.skywalking.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2020/08/05/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/apache/skywalking/pull/4970",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6%40%3Cdev.skywalking.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases."
    },
    {
      "lang": "es",
      "value": "** Resuelto** Solo cuando se usa H2/MySQL/TiDB como almacenamiento Apache SkyWalking, existe una vulnerabilidad de inyección SQL en los casos de consulta comodín"
    }
  ],
  "lastModified": "2026-06-17T02:53:54.080",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:skywalking:6.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E62A23B6-6BE7-47F7-88A5-6EFC34A2566F"
            },
            {
              "criteria": "cpe:2.3:a:apache:skywalking:6.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F51FACC0-3D78-437A-BC9C-6D5550CFB48D"
            },
            {
              "criteria": "cpe:2.3:a:apache:skywalking:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5C5A2EB-0DF4-4172-BEDB-2D7ED9F43917"
            },
            {
              "criteria": "cpe:2.3:a:apache:skywalking:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9EEB0AC-DE2A-41AE-B62B-26A2A0118EE5"
            },
            {
              "criteria": "cpe:2.3:a:apache:skywalking:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6C3300E-F3F5-4CF2-9670-FE50DA4599AD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}