CVE-2020-1937: Apache Kylin
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
Affected products
- Apache Kylin: from 2.3.0, up to and including 2.3.2; from 2.4.0, up to and including 2.4.1; from 2.5.0, up to and including 2.5.2; from 2.6.0, up to and including 2.6.4; version 3.0.0 only
Published 2020-02-24. Last modified 2026-06-17.