Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12NWdqLWZ4M2ctaGNwd84AA3TT

SQL injection in Apache Submarine

Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login.

Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins.

If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.

Permalink: https://github.com/advisories/GHSA-v5gj-fx3g-hcpw
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NWdqLWZ4M2ctaGNwd84AA3TT
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-v5gj-fx3g-hcpw, CVE-2023-37924
References: Repository: https://github.com/apache/submarine
Blast Radius: 0.0

Affected Packages

pypi:apache-submarine
Dependent packages: 0
Dependent repositories: 1
Downloads: 1,045 last month
Affected Version Ranges: >= 0.7.0, < 0.8.0
Fixed in: 0.8.0
All affected versions: 0.7.0
All unaffected versions: 0.4.0, 0.5.0, 0.6.0, 0.8.0