CVE Vulnerabilities

CVE-2020-13937

Insecure Storage of Sensitive Information

Published: Oct 19, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylins configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
KylinApache2.0.0 (including)2.0.0 (including)
KylinApache2.1.0 (including)2.1.0 (including)
KylinApache2.2.0 (including)2.2.0 (including)
KylinApache2.3.0 (including)2.3.0 (including)
KylinApache2.3.1 (including)2.3.1 (including)
KylinApache2.3.2 (including)2.3.2 (including)
KylinApache2.4.0 (including)2.4.0 (including)
KylinApache2.4.1 (including)2.4.1 (including)
KylinApache2.5.0 (including)2.5.0 (including)
KylinApache2.5.1 (including)2.5.1 (including)
KylinApache2.5.2 (including)2.5.2 (including)
KylinApache2.6.0 (including)2.6.0 (including)
KylinApache2.6.1 (including)2.6.1 (including)
KylinApache2.6.2 (including)2.6.2 (including)
KylinApache2.6.3 (including)2.6.3 (including)
KylinApache2.6.4 (including)2.6.4 (including)
KylinApache2.6.5 (including)2.6.5 (including)
KylinApache2.6.6 (including)2.6.6 (including)
KylinApache3.0.0 (including)3.0.0 (including)
KylinApache3.0.0-alpha (including)3.0.0-alpha (including)
KylinApache3.0.0-alpha2 (including)3.0.0-alpha2 (including)
KylinApache3.0.0-beta (including)3.0.0-beta (including)
KylinApache3.0.1 (including)3.0.1 (including)
KylinApache3.0.2 (including)3.0.2 (including)
KylinApache3.1.0 (including)3.1.0 (including)
KylinApache4.0.0-alpha (including)4.0.0-alpha (including)

References