Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwcg-wv5x-vg3g

Опубликовано: 12 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Apache Submarine Commons Utils has a hard-coded secret

Improper Authentication vulnerability in Apache Submarine Commons Utils.

This issue affects Apache Submarine Commons Utils: from 0.8.0.

As this project is retired, we do not plan to release a version that fixes this issue. If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Пакеты

Наименование

org.apache.submarine:submarine-commons-utils

maven
Затронутые версииВерсия исправления

<= 0.8.0

Отсутствует

Наименование

apache-submarine

pip
Затронутые версииВерсия исправления

>= 0.8.0

Отсутствует

EPSS

Процентиль: 45%
0.00224
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 45%
0.00224
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-798