CVE-2020-1937: Apache Kylin

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

Affected products

  • Apache Kylin: from 2.3.0, up to and including 2.3.2; from 2.4.0, up to and including 2.4.1; from 2.5.0, up to and including 2.5.2; from 2.6.0, up to and including 2.6.4; version 3.0.0 only

Published 2020-02-24. Last modified 2026-06-17.