Improper Authentication Affecting org.apache.submarine:submarine-commons-utils package, versions [0.8.0,]
Threat Intelligence
EPSS
0.23% (62nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHESUBMARINE-7251689
- published 13 Jun 2024
- disclosed 12 Jun 2024
- credit Jonathan Leitschuh, L0ne1y
Introduced: 12 Jun 2024
CVE-2024-36264 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
Affected versions of this package are vulnerable to Improper Authentication due to the use of a hard-coded secret. An attacker can gain unauthorized access or perform unauthorized operations by exploiting the hardcoded credentials.
Note: This vulnerability only affects products that are no longer supported by the maintainer. A fix release is not expected.