RULE(RULE ID:715008)

Rule General Information
Release Date: 2021-07-23
Rule Name: Apache SkyWalking SQL Injection Vulnerability (CVE-2020-13921)
Severity:
CVE ID:
Rule Protection Details
Description: Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: http://www.openwall.com/lists/oss-security/2020/08/05/3
https://github.com/apache/skywalking/pull/4970
https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://lists.apache.org/thread.html/r6f3a934ebc54585d8468151a494c1919dc1ee2cccaf237ec434dbbd6@%3Cdev.skywalking.apache.org%3E