Описание
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set submarine.auth.default.secret, a default value will be used.
This issue affects Apache Submarine Commons Utils: from 0.8.0.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Ссылки
- Issue TrackingPatchVendor Advisory
- Mailing ListVendor Advisory
- Issue TrackingPatchVendor Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.8.0 (включая)
cpe:2.3:a:apache:submarine:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00224
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287
NVD-CWE-Other
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
Apache Submarine Commons Utils has a hard-coded secret
EPSS
Процентиль: 45%
0.00224
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-287
NVD-CWE-Other