CVE Vulnerabilities

CVE-2020-13937

Insecure Storage of Sensitive Information

Published: Oct 19, 2020 | Modified: Oct 29, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylins configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Kylin Apache 2.0.0 (including) 2.0.0 (including)
Kylin Apache 2.1.0 (including) 2.1.0 (including)
Kylin Apache 2.2.0 (including) 2.2.0 (including)
Kylin Apache 2.3.0 (including) 2.3.0 (including)
Kylin Apache 2.3.1 (including) 2.3.1 (including)
Kylin Apache 2.3.2 (including) 2.3.2 (including)
Kylin Apache 2.4.0 (including) 2.4.0 (including)
Kylin Apache 2.4.1 (including) 2.4.1 (including)
Kylin Apache 2.5.0 (including) 2.5.0 (including)
Kylin Apache 2.5.1 (including) 2.5.1 (including)
Kylin Apache 2.5.2 (including) 2.5.2 (including)
Kylin Apache 2.6.0 (including) 2.6.0 (including)
Kylin Apache 2.6.1 (including) 2.6.1 (including)
Kylin Apache 2.6.2 (including) 2.6.2 (including)
Kylin Apache 2.6.3 (including) 2.6.3 (including)
Kylin Apache 2.6.4 (including) 2.6.4 (including)
Kylin Apache 2.6.5 (including) 2.6.5 (including)
Kylin Apache 2.6.6 (including) 2.6.6 (including)
Kylin Apache 3.0.0 (including) 3.0.0 (including)
Kylin Apache 3.0.0-alpha (including) 3.0.0-alpha (including)
Kylin Apache 3.0.0-alpha2 (including) 3.0.0-alpha2 (including)
Kylin Apache 3.0.0-beta (including) 3.0.0-beta (including)
Kylin Apache 3.0.1 (including) 3.0.1 (including)
Kylin Apache 3.0.2 (including) 3.0.2 (including)
Kylin Apache 3.1.0 (including) 3.1.0 (including)
Kylin Apache 4.0.0-alpha (including) 4.0.0-alpha (including)

References