PT-2024-26940 · Apache · Apache Submarine Commons Utils

Jonathan Leitschuh

+1

·

Published

2024-06-12

·

Updated

2024-10-15

·

CVE-2024-36264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Submarine Commons Utils versions 0.8.0 and later
Description The issue is related to an Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used. This vulnerability only affects products that are no longer supported by the maintainer. As the project is retired, no fix will be released.
Recommendations For Apache Submarine Commons Utils versions 0.8.0 and later, users are recommended to find an alternative or restrict access to the instance to trusted users.

Fix

Improper Authentication

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-36264
GHSA-JWCG-WV5X-VG3G
PYSEC-2024-97

Affected Products

Apache Submarine Commons Utils