← Back

CVE-2020-13937

Published: Oct 19, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

Affected (26)

Products: Apache: Kylin
1 product
Kylin
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.0.0
Version 2.1.0
Version 2.2.0
Version 2.3.0
Version 2.3.1
Version 2.3.2
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.6
Version 3.0.0
Version 3.0.0 alpha2
Version 3.0.0 alpha
Version 3.0.0 beta
Version 3.0.1
Version 3.0.2
Version 3.1.0
Version 4.0.0 alpha

Timeline

No history available yet.