** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/apache/submarine/pull/1125 | issue tracking patch vendor advisory |
https://lists.apache.org/thread/7mo0c7vbhpo8thvybl8wwvb0bccrg7r4 | mailing list vendor advisory |
http://www.openwall.com/lists/oss-security/2024/06/12/2 |