Moderate severityNVD Advisory· Published Jun 12, 2024· Updated Mar 20, 2025
Apache Submarine Commons Utils: default secret
CVE-2024-36264
Description
UNSUPPORTED WHEN ASSIGNED Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used.
This issue affects Apache Submarine Commons Utils: from 0.8.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.submarine:submarine-commons-utilsMaven | <= 0.8.0 | — |
apache-submarinePyPI | >= 0.8.0 | — |
Affected products
3- ghsa-coords2 versions
<= 0.8.0+ 1 more
- (no CPE)range: <= 0.8.0
- (no CPE)range: >= 0.8.0
- Range: 0.8.0
Patches
Vulnerability mechanics
References
8- github.com/apache/submarine/pull/1125ghsapatchWEB
- github.com/advisories/GHSA-jwcg-wv5x-vg3gghsaADVISORY
- lists.apache.org/thread/7mo0c7vbhpo8thvybl8wwvb0bccrg7r4ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-36264ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/06/12/2ghsaWEB
- github.com/apache/submarine/commit/7a1d551798c6785fc68fe028fc46f74c3ee6976dghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2024-97.yamlghsaWEB
- issues.apache.org/jira/browse/SUBMARINE-1417ghsaWEB
News mentions
0No linked articles in our index yet.