org.apache.submarine:submarine-commons-utils@0.8.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.submarine:submarine-commons-utils package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Improper Authentication

Affected versions of this package are vulnerable to Improper Authentication due to the use of a hard-coded secret. An attacker can gain unauthorized access or perform unauthorized operations by exploiting the hardcoded credentials.

Note: This vulnerability only affects products that are no longer supported by the maintainer. A fix release is not expected.

How to fix Improper Authentication?

A fix was pushed into the master branch but not yet published.

[0.8.0,)
  • H
Missing Authentication for Critical Function

Affected versions of this package are vulnerable to Missing Authentication for Critical Function that allows attackers to generate unauthorized JWT tokens, due to a hard-coded default secret value.

Note: A fixed release is not expected as this package is no longer maintained, but a patch has been added to the repository that retrieves SUBMARINE_AUTH_DEFAULT_SECRET from an environment variable rather than using a hard-coded value.

How to fix Missing Authentication for Critical Function?

A fix was pushed into the master branch but not yet published.

[0.8.0,)