cbcvebase.
CVE-2024-36264
published 2024-06-12

CVE-2024-36264: ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.

If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used.


This issue affects Apache Submarine Commons Utils: from 0.8.0.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachesubmarine>= 0.8.0
apache_software_foundationapache_submarine_commons_utils0.8.0 – *