CVE-2024-36264: Apache Submarine Commons Utils: default secret
UNSUPPORTED WHEN ASSIGNED Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used.
This issue affects Apache Submarine Commons Utils: from 0.8.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
Improper Authentication vulnerability in Apache Submarine Commons Utils.
This issue affects Apache Submarine Commons Utils: from 0.8.0.
As this project is retired, we do not plan to release a version that fixes this issue. If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36264?
CVE-2024-36264 is categorized as an improper authentication vulnerability that could lead to unauthorized access.
How do I fix CVE-2024-36264?
To fix CVE-2024-36264, ensure that the 'submarine.auth.default.secret' parameter is explicitly set to a secure value.
Which versions of Apache Submarine are affected by CVE-2024-36264?
CVE-2024-36264 affects Apache Submarine Commons Utils from version 0.8.0 onwards.
What software component is impacted by CVE-2024-36264?
CVE-2024-36264 impacts the Apache Submarine Commons Utils component.
Is there a known exploit for CVE-2024-36264?
As of now, there are no publicly known exploits specific to CVE-2024-36264.