CVE-2024-36264

Description

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.If the user doesnt explicitly set submarine.auth.default.secret, a default value will be used.This issue affects Apache Submarine Commons Utils: from 0.8.0.As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.221

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2024-36264 are affected in Apache - submarine-commons-utils 0.8.0Windows
Vulnerabilities CVE-2024-36264 are affected in Apache - submarine-commons-utils for Linux 0.8.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234