First published: Mon Oct 19 2020(Updated: )
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Kylin | =2.0.0 | |
Apache Kylin | =2.1.0 | |
Apache Kylin | =2.2.0 | |
Apache Kylin | =2.3.0 | |
Apache Kylin | =2.3.1 | |
Apache Kylin | =2.3.2 | |
Apache Kylin | =2.4.0 | |
Apache Kylin | =2.4.1 | |
Apache Kylin | =2.5.0 | |
Apache Kylin | =2.5.1 | |
Apache Kylin | =2.5.2 | |
Apache Kylin | =2.6.0 | |
Apache Kylin | =2.6.1 | |
Apache Kylin | =2.6.2 | |
Apache Kylin | =2.6.3 | |
Apache Kylin | =2.6.4 | |
Apache Kylin | =2.6.5 | |
Apache Kylin | =2.6.6 | |
Apache Kylin | =3.0.0 | |
Apache Kylin | =3.0.0-alpha | |
Apache Kylin | =3.0.0-alpha2 | |
Apache Kylin | =3.0.0-beta | |
Apache Kylin | =3.0.1 | |
Apache Kylin | =3.0.2 | |
Apache Kylin | =3.1.0 | |
Apache Kylin | =4.0.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13937 is a vulnerability in Apache Kylin versions 2.0.0 to 2.6.6 and 3.0.0-alpha to 4.0.0-alpha that exposes Kylin's configuration information without authentication.
CVE-2020-13937 has a severity level of 5.3, which is considered medium.
You can check if your Apache Kylin version is affected by CVE-2020-13937 by referring to the list of affected versions provided in the vulnerability description.
To fix CVE-2020-13937, it is recommended to upgrade to a patched version of Apache Kylin that addresses the vulnerability.
You can find more information about CVE-2020-13937 on the Apache Kylin mailing list thread provided in the references.