CVE-2023-37924
Last modified
CVE-2023-37924 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this. . EPSS estimates a 7.17% chance of exploitation in the next 30 days.
Description
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Submarine | >= 0.7.0, < 0.8.0 |
References
- https://github.com/apache/submarine/pull/1037Issue Tracking
- https://issues.apache.org/jira/browse/SUBMARINE-1361Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3rMailing List, Vendor Advisory
- https://github.com/apache/submarine/pull/1037Issue Tracking
- https://issues.apache.org/jira/browse/SUBMARINE-1361Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3rMailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37924?
How severe is CVE-2023-37924?
How do I fix CVE-2023-37924?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37919Cal.com is open-source scheduling software. A vulnerability …5.4
- CVE-2023-3792A vulnerability was found in Beijing Netcon NS-ASG 6.3. It h…6.5
- CVE-2023-37920Certifi is a curated collection of Root Certificates for val…9.8
- CVE-2023-37921Multiple arbitrary write vulnerabilities exist in the VCD so…7.8
- CVE-2023-37922Multiple arbitrary write vulnerabilities exist in the VCD so…7.8
- CVE-2023-37923Multiple arbitrary write vulnerabilities exist in the VCD so…7.8
- CVE-2023-37925An improper privilege management vulnerability in the debug …5.5
- CVE-2023-37926A buffer overflow vulnerability in the Zyxel ATP series firm…5.5
- CVE-2023-37927The improper neutralization of special elements in the CGI p…8.8
- CVE-2023-37928A post-authentication command injection vulnerability in the…8.8
- CVE-2023-37929The buffer overflow vulnerability in the CGI program of the …6.5
- CVE-2023-3793A vulnerability was found in Weaver e-cology. It has been ra…9.8
Are you affected by CVE-2023-37924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
