CVE-2020-10590
Last modified
CVE-2020-10590 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Replicated | Replicated Classic | >= 2.10.0, <= 2.32.3 |
| Replicated | Replicated Classic | >= 2.33.0, <= 2.36.0 |
| Replicated | Replicated Classic | >= 2.37.0, <= 2.37.1 |
| Replicated | Replicated Classic | >= 2.38.0, <= 2.38.5 |
| Replicated | Replicated Classic | >= 2.39.0, <= 2.39.3 |
| Replicated | Replicated Classic | >= 2.40.0, <= 2.40.3 |
| Replicated | Replicated Classic | >= 2.42.0, <= 2.42.3 |
| Replicated | Replicated Classic | 2.41.0 |
References
- https://blog.replicated.comVendor Advisory
- https://gradle.com/enterprise/releases/2019.5/#changesThird Party Advisory
- https://blog.replicated.comVendor Advisory
- https://gradle.com/enterprise/releases/2019.5/#changesThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10590?
How severe is CVE-2020-10590?
How do I fix CVE-2020-10590?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10583The /admin/admapi.php script of Invigo Automatic Device Mana…8.8
- CVE-2020-10584A directory traversal on the /admin/search_by.php script of …7.5
- CVE-2020-10587antiX and MX Linux allow local users to achieve root access …7.8
- CVE-2020-10588v2rayL 2.1.3 allows local users to achieve root access becau…7.8
- CVE-2020-10589v2rayL 2.1.3 allows local users to achieve root access becau…7.8
- CVE-2020-1059A spoofing vulnerability exists when Microsoft Edge does not…4.3
- CVE-2020-10591An issue was discovered in Walmart Labs Concord before 1.44.…7.5
- CVE-2020-10592Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x befor…7.5
- CVE-2020-10593Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x befor…7.5
- CVE-2020-10594An issue was discovered in drf-jwt 1.15.x before 1.15.1. It …9.1
- CVE-2020-10595pam-krb5 before 4.9 has a buffer overflow that might cause r…9.8
- CVE-2020-10596OpenCart 3.0.3.2 allows remote authenticated users to conduc…5.4
Are you affected by CVE-2020-10590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
