CVE-2020-10590
Summary
| CVE | CVE-2020-10590 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-30 14:15:00 UTC |
| Updated | 2022-06-28 14:11:00 UTC |
| Description | Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Replicated | Replicated Classic | 2.41.0 | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
| Application | Replicated | Replicated Classic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-10590 - Replicated | MISC | www.replicated.com | |
| 2019.5 | Gradle Enterprise | CONFIRM | gradle.com | |
| Replicated Blog | MISC | blog.replicated.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.