CVE-2020-13937
published 2020-10-19CVE-2020-13937: Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha…
PriorityP261medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EXPLOIT
EPSS
78.33%
99.5th percentile
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
| apache | kylin | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Unauthenticated HTTP GET request to /kylin/api/admin/config returns HTTP 200 with Content-Type: application/json and body containing both 'config' and 'kylin.metadata.url' — confirms vulnerable exposed configuration endpoint. ↗
- →Use Shodan favicon hash -186961397 or FOFA icon_hash=-186961397 to identify internet-exposed Apache Kylin instances for proactive scanning. ↗
- ·Affected versions span a wide range: Apache Kylin 2.0.0 through 3.1.0 and 4.0.0-alpha. Detection logic should not be version-gated — the unauthenticated endpoint is the reliable indicator. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication bypass in Apache Kylin
osv·2022-02-10
CVE-2020-13937 [MEDIUM] Authentication bypass in Apache Kylin
Authentication bypass in Apache Kylin
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
GHSA
Authentication bypass in Apache Kylin
ghsa·2022-02-10
CVE-2020-13937 [MEDIUM] CWE-922 Authentication bypass in Apache Kylin
Authentication bypass in Apache Kylin
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
No detection rules found.
Nuclei
Apache Kylin - Exposed Configuration File
nuclei·CVSS 5.3
CVE-2020-13937 [MEDIUM] Apache Kylin - Exposed Configuration File
Apache Kylin - Exposed Configuration File
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha have one REST API which exposed Kylin's configuration information without authentication.
Template:
id: CVE-2020-13937
info:
name: Apache Kylin - Exposed Configuration File
author: pikpikcu
severity: medium
description: Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha have one REST API which exposed Kylin's configuration information without authentication.
impact:
No writeups or analysis indexed.
2020-10-19
Published