Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS12NWdqLWZ4M2ctaGNwd84AA3TT
SQL injection in Apache Submarine
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login.
Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins.
If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.
Permalink: https://github.com/advisories/GHSA-v5gj-fx3g-hcpwJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NWdqLWZ4M2ctaGNwd84AA3TT
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 1 year ago
Updated: about 1 year ago
CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-v5gj-fx3g-hcpw, CVE-2023-37924
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-37924
- https://github.com/apache/submarine/pull/1037
- https://issues.apache.org/jira/browse/SUBMARINE-1361
- https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3r
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2023-244.yaml
- https://github.com/apache/submarine/commit/4cd2af10499ac6dc4f82bda179d9f414a522abef
- https://github.com/advisories/GHSA-v5gj-fx3g-hcpw
Blast Radius: 0.0
Affected Packages
pypi:apache-submarine
Dependent packages: 0Dependent repositories: 1
Downloads: 1,045 last month
Affected Version Ranges: >= 0.7.0, < 0.8.0
Fixed in: 0.8.0
All affected versions: 0.7.0
All unaffected versions: 0.4.0, 0.5.0, 0.6.0, 0.8.0