CVE-2020-13937

Source
https://cve.org/CVERecord?id=CVE-2020-13937
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13937.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13937
Aliases
Published
2020-10-19T21:15:12.623Z
Modified
2026-04-10T04:22:27.432982Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

References

Affected packages

Git / github.com/apache/kylin

Affected ranges

Type
GIT
Repo
https://github.com/apache/kylin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.6.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0-alpha"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0-alpha2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0-beta"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.0.0-alpha"
        }
    ]
}

Affected versions

kylin-2.*
kylin-2.0.0
kylin-2.1.0
kylin-2.2.0
kylin-2.3.0
kylin-2.3.1
kylin-2.3.2
kylin-2.4.0
kylin-2.4.1
kylin-2.5.0
kylin-2.5.1
kylin-2.5.2
kylin-2.6.0
kylin-2.6.1
kylin-2.6.2
kylin-2.6.3
kylin-2.6.4
kylin-2.6.5
kylin-2.6.6
kylin-3.*
kylin-3.0.0
kylin-3.0.0-alpha
kylin-3.0.0-alpha2
kylin-3.0.0-beta
kylin-3.0.1
kylin-3.0.2
kylin-3.1.0
kylin-4.*
kylin-4.0.0-alpha
v0.*
v0.6.1
v0.6.1_mysql_auth

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13937.json"