← All CVEs

CVE-2020-13937

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

5.3
CVSS
78.3%
EPSS (exploit prob.)
100th
EPSS percentile
2020-10-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-922

Affected products

VendorProductAffected versions
apachekylin2.0.0
apachekylin2.1.0
apachekylin2.2.0
apachekylin2.3.0
apachekylin2.3.1
apachekylin2.3.2
apachekylin2.4.0
apachekylin2.4.1
apachekylin2.5.0
apachekylin2.5.1
apachekylin2.5.2
apachekylin2.6.0
apachekylin2.6.1
apachekylin2.6.2
apachekylin2.6.3
apachekylin2.6.4
apachekylin2.6.5
apachekylin2.6.6
apachekylin3.0.0
apachekylin3.0.0
apachekylin3.0.0
apachekylin3.0.0
apachekylin3.0.1
apachekylin3.0.2
apachekylin3.1.0
apachekylin4.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-13937