Improper Authentication in Apache Submarine Commons Utils by Apache
CVE-2024-36264
9.8CRITICAL
Summary
An improper authentication vulnerability exists in Apache Submarine Commons Utils, which arises when users fail to explicitly set the 'submarine.auth.default.secret' configuration. In such cases, the software defaults to a predefined secret that may not offer adequate security, exposing the system to unauthorized access. This vulnerability is particularly concerning as it affects a retired project, meaning no further patches will be developed to address this issue. Users are advised to seek alternative solutions or limit access to the application only to trusted users to mitigate potential security risks.
Affected Version(s)
Apache Submarine Commons Utils 0.8.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published