AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .9734 99.9 YES
AFFECTED Product Versions Fixed Kylin 2.3.0 – —
TIMELINE Dec 2 Reserved by apache May 22 Published (CNA: apache) Mar 25 Added to CISA KEV, remediation due 2022-04-15
Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .9734 99.9 YES
AFFECTED Product Versions Fixed Kylin 2.3.0 – —
TIMELINE Dec 2 Reserved by apache May 22 Published (CNA: apache) Mar 25 Added to CISA KEV, remediation due 2022-04-15
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
| Date | Event | Detail |
|---|---|---|
| December 2, 2019 | Reserved | Reserved by apache |
| May 22, 2020 | Published | Published (CNA: apache) |
| March 25, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-04-15 |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| Apache | Kylin | — | 2.3.0 | — |
Authoritative record: CVE-2020-1956 at cve.org
Vendors: apache
Weaknesses: CWE-78
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2020-1956 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.