PT-2024-26940 · Apache · Apache Submarine Commons Utils
Jonathan Leitschuh
+1
·
Published
2024-06-12
·
Updated
2024-10-15
·
CVE-2024-36264
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Submarine Commons Utils versions 0.8.0 and later
Description
The issue is related to an Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set
submarine.auth.default.secret, a default value will be used. This vulnerability only affects products that are no longer supported by the maintainer. As the project is retired, no fix will be released.Recommendations
For Apache Submarine Commons Utils versions 0.8.0 and later, users are recommended to find an alternative or restrict access to the instance to trusted users.
Fix
Improper Authentication
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Submarine Commons Utils