CVE-2024-36265

🟠 Łataj w tym tygodniu

Obejście uwierzytelnienia w Apache Submarine Server Core umożliwia nieautoryzowany dostęp.

CVSS
9.8
EPSS
0.7%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

auth-bypass Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.7%
Opublikowano (NVD)2024-06-12 15:15:52 UTC
Ostatnia modyfikacja (NVD)2026-07-14 11:16:46 UTC
Referencje