CVE-2023-37924
Last modified
CVE-2023-37924 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this. . EPSS estimates a 7.17% chance of exploitation in the next 30 days.
Description
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Submarine | >= 0.7.0, < 0.8.0 |
References
- https://github.com/apache/submarine/pull/1037Issue Tracking
- https://issues.apache.org/jira/browse/SUBMARINE-1361Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3rMailing List, Vendor Advisory
- https://github.com/apache/submarine/pull/1037Issue Tracking
- https://issues.apache.org/jira/browse/SUBMARINE-1361Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3rMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37924?
How severe is CVE-2023-37924?
How do I fix CVE-2023-37924?
Are you affected by CVE-2023-37924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
