Publish Advisories

GHSA-cc55-mvqc-g9mg
GHSA-jwcg-wv5x-vg3g
GHSA-w7cp-g8v7-r54m
This commit is contained in:
advisory-database[bot]
2025-03-21 04:29:38 +00:00
parent abbbef87d2
commit cd5c7b5462
3 changed files with 4 additions and 4 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-mvqc-g9mg",
"modified": "2024-06-12T19:45:06Z",
"modified": "2025-03-21T04:28:09Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-37629"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwcg-wv5x-vg3g",
"modified": "2024-10-14T20:16:58Z",
"modified": "2025-03-21T04:28:28Z",
"published": "2024-06-12T15:31:44Z",
"aliases": [
"CVE-2024-36264"
],
"summary": "Apache Submarine Commons Utils has a hard-coded secret",
"details": "Improper Authentication vulnerability in Apache Submarine Commons Utils.\n\nThis issue affects Apache Submarine Commons Utils: from 0.8.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. Users are recommended to find an alternative or restrict access to the instance to trusted users. \n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n",
"details": "Improper Authentication vulnerability in Apache Submarine Commons Utils.\n\nThis issue affects Apache Submarine Commons Utils: from 0.8.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. Users are recommended to find an alternative or restrict access to the instance to trusted users. \n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7cp-g8v7-r54m",
"modified": "2025-01-21T18:00:48Z",
"modified": "2025-03-21T04:28:49Z",
"published": "2024-08-21T18:31:27Z",
"aliases": [
"CVE-2024-41937"