5.3

CVE-2020-13937

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheKylin Version2.0.0
ApacheKylin Version2.1.0
ApacheKylin Version2.2.0
ApacheKylin Version2.3.0
ApacheKylin Version2.3.1
ApacheKylin Version2.3.2
ApacheKylin Version2.4.0
ApacheKylin Version2.4.1
ApacheKylin Version2.5.0
ApacheKylin Version2.5.1
ApacheKylin Version2.5.2
ApacheKylin Version2.6.0
ApacheKylin Version2.6.1
ApacheKylin Version2.6.2
ApacheKylin Version2.6.3
ApacheKylin Version2.6.4
ApacheKylin Version2.6.5
ApacheKylin Version2.6.6
ApacheKylin Version3.0.0 Update-
ApacheKylin Version3.0.0 Updatealpha
ApacheKylin Version3.0.0 Updatealpha2
ApacheKylin Version3.0.0 Updatebeta
ApacheKylin Version3.0.1
ApacheKylin Version3.0.2
ApacheKylin Version3.1.0
ApacheKylin Version4.0.0 Updatealpha
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.35% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-922 Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.