Apache Submarine Server Core: authorization bypass
CVE-2024-36265
9.8CRITICAL
What is CVE-2024-36265?
An incorrect authorization vulnerability has been identified in Apache Submarine Server Core, affecting version 0.8.0 and later. As this project has been retired, no further support or patches will be provided to address this issue. Users operating this product are strongly advised to seek alternative solutions or implement stringent access restrictions to safeguard their instances. The lack of ongoing support emphasizes the importance of migrating to a maintained product to ensure continued protection against security threats.
Affected Version(s)
Apache Submarine Server Core 0.8.0