id: PYSEC-2024-97 modified: 2024-09-26T17:22:54.470974Z published: 2024-06-12T14:15:00Z aliases: - CVE-2024-36264 - GHSA-jwcg-wv5x-vg3g details: |+ ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. affected: - package: ecosystem: PyPI name: apache-submarine purl: pkg:pypi/apache-submarine ranges: - type: ECOSYSTEM events: - introduced: 0.8.0 versions: - 0.8.0 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H references: - type: REPORT url: https://github.com/apache/submarine/pull/1125 - type: FIX url: https://github.com/apache/submarine/pull/1125 - type: ADVISORY url: https://github.com/apache/submarine/pull/1125 - type: ARTICLE url: https://lists.apache.org/thread/7mo0c7vbhpo8thvybl8wwvb0bccrg7r4 - type: ADVISORY url: https://lists.apache.org/thread/7mo0c7vbhpo8thvybl8wwvb0bccrg7r4 - type: ARTICLE url: http://www.openwall.com/lists/oss-security/2024/06/12/2 - type: WEB url: http://www.openwall.com/lists/oss-security/2024/06/12/2 - type: ADVISORY url: https://github.com/advisories/GHSA-jwcg-wv5x-vg3g