Junglewise Threat Intelligence

CVE-2024-36265: PYSEC-2024-98 - ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine

CVE-2024-36265 · Severity: low · CVSS 3.1 · Published 2024-06-12

Technologies: apache-submarine (PyPI). Vendors: Maven, PyPI.

Executive brief

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.

This issue affects Apache Submarine Server Core: from 0.8.0.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

  • Maven org.apache.submarine:submarine-server-core
  • PyPI apache-submarine

Related threats