kylinGHSA-2hpg-vwqj-6h6w
Authentication bypass in Apache Kylin
Medium5.3CVE-2020-13937 · Published Feb 10, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kylin:kylin Maven | < 3.1.1 | 3.1.1 |
| >= 4.0.0-alpha, < 4.0.0-beta | 4.0.0-beta |
Details and references
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-922
- Also known as
- CVE-2020-13937
More kylin advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 82022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. CVE-2021-45457High7.5fixed in 3.1.3, 4.0.1 | High7.5 | 3.1.3, 4.0.1 |
| Jan 82022 | Use of Hard-coded Credentials in Apache Kylin CVE-2021-45458High7.5fixed in 3.1.3, 4.0.1 | High7.5 | 3.1.3, 4.0.1 |
| Jan 82022 | SQL Injection in Apache Kylin CVE-2021-36774Medium6.5fixed in 3.1.3 | Medium6.5 | 3.1.3 |
| Jan 82022 | Server-Side Request Forgery in Apache Kylin CVE-2021-27738Mediumfixed in 3.1.3 | Medium | 3.1.3 |
| Jan 82022 | Kylin can receive user input and load any class through Class.forName(...). CVE-2021-31522Mediumfixed in 3.1.3, 4.0.1 | Medium | 3.1.3, 4.0.1 |
| Jan 82022 | Command Injection in Apache Kylin CVE-2021-45456Mediumfixed in 4.0.1 | Medium | 4.0.1 |