CVE-2020-13937

MEDIUM NUCLEI

Apache Kylin <4.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2020-13937. PoCs published by yaunsky, Al1ex, kailing0220. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a Python script that scans for the Apache Kylin API unauthorized access vulnerability (CVE-2020-13937). It checks if the `/kylin/api/admin/config` endpoint is accessible without authentication.

Description

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

Exploits (3)

nomisec SCANNER 9 stars
by yaunsky · poc
https://github.com/yaunsky/CVE-2020-13937

This repository contains a Python script that scans for the Apache Kylin API unauthorized access vulnerability (CVE-2020-13937). It checks if the `/kylin/api/admin/config` endpoint is accessible without authentication.

Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache Kylin
No auth needed
Prerequisites: Target URL or file containing target URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 5 stars
by Al1ex · poc
https://github.com/Al1ex/CVE-2020-13937

This repository describes an information disclosure vulnerability in Apache Kylin where an unauthenticated API endpoint exposes sensitive configuration details. The exploit involves accessing a specific RESTful API endpoint to retrieve confidential information.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Kylin versions 2.0.0 through 4.0.0-alpha
No auth needed
Prerequisites: Network access to the target Apache Kylin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by kailing0220 · poc
https://github.com/kailing0220/CVE-2020-13937

This is a functional PoC for CVE-2020-13937, an unauthorized access vulnerability in Apache Kylin. It checks for the exposure of configuration information via an unauthenticated RESTful API endpoint.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Kylin (all versions)
No auth needed
Prerequisites: Network access to the target Apache Kylin instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Apache Kylin - Exposed Configuration File
MEDIUMby pikpikcu
Shodan: http.favicon.hash:-186961397
FOFA: icon_hash=-186961397

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.7881
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-922
Status published
Products (24)
apache/kylin 2.0.0
apache/kylin 2.1.0
apache/kylin 2.2.0
apache/kylin 2.3.0
apache/kylin 2.3.1
apache/kylin 2.3.2
apache/kylin 2.4.0
apache/kylin 2.4.1
apache/kylin 2.5.0
apache/kylin 2.5.1
... and 14 more
Published Oct 19, 2020
Tracked Since Feb 18, 2026