← Vulnerability feed

Vulnerability record · CVE-2020-13937 · published 19 October 2020

CVE-2020-13937: Apache Kylin REST API exposes configuration without authentication

Apache · Kylin

Apache Kylin ships a RESTful API endpoint that returns the server's configuration information without requiring any authentication. Because configuration files often contain credentials, connection strings and other confidential entries, any network-reachable instance leaks sensitive data to unauthenticated users. The flaw affects a long list of Kylin releases from 2.0.0 through 4.0.0-alpha.

5.3 CVSS 3.1 Medium EPSS 78% · top 0.4% CWE-922 · CWE-922
5.3CVSS 3.1 base score, v2 5.0
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is trivially exploitable without authentication and has a very high EPSS score, though CVSS rates the direct impact as medium and there is no KEV listing.

What it is

Apache Kylin ships a RESTful API endpoint that returns the server's configuration information without requiring any authentication. Because configuration files often contain credentials, connection strings and other confidential entries, any network-reachable instance leaks sensitive data to unauthenticated users. The flaw affects a long list of Kylin releases from 2.0.0 through 4.0.0-alpha.

Impact

An unauthenticated attacker gains read access to Kylin configuration data, which can include credentials and internal system details useful for follow-on attacks. The direct impact is confidentiality loss only; there is no integrity or availability effect.

Attack surface

Reachable over the network via the Kylin REST API (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are required. Any host exposing the Kylin web service is a candidate.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.783 probability, 99.6th percentile), indicating elevated likelihood of exploitation activity. The only references are the Apache vendor advisory and release notes; no public exploit code is cited in the record.

What to do

  • Upgrade Apache Kylin to a release that fixes the unauthenticated configuration API; consult the Apache Kylin advisory for the fixed version.
  • If upgrade is not immediately possible, restrict network access to the Kylin REST API to trusted hosts using firewall rules or a reverse proxy.
  • Require authentication at the fronting proxy for all Kylin API paths, especially configuration endpoints.
  • Rotate any credentials or secrets that may have been stored in Kylin configuration and exposed.
  • Monitor Kylin configuration files for plaintext secrets and move them to a secrets manager.

Detection

  • Search web/proxy logs for unauthenticated requests to Kylin configuration API paths and flag any that return HTTP 200.
  • Baseline which clients normally call the Kylin REST API and alert on new or external source IPs hitting configuration endpoints.
  • Inspect Kylin configuration responses for secret-like values and alert if such endpoints are reachable from untrusted networks.
  • Use network monitoring to detect scanning or enumeration of Kylin API paths from outside expected segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13937 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-1956Apache Kylin REST API OS command injectionApache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated…KEVEPSS 97%analysed9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2022-24697Apache Kylin cube designer OS command injection via config overrideApache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the va…EPSS 85%analysed9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2021-45456Apache Kylin DiagnosisService project name check mismatch allows command injectionApache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell com…EPSS 89%analysed9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2020-13937), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.