Skip to content

Al1ex/CVE-2020-13937

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

Description

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

How to Exploit

http://xx.com/kylin/api/admin/config

result

Reference

https://nvd.nist.gov/vuln/detail/CVE-2020-13937

About

Apache Kylin API Unauthorized Access

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published