Lucene search

K
githubGitHub Advisory DatabaseGHSA-V74C-QC46-9GG9
HistoryJun 12, 2024 - 3:31 p.m.

Apache Submarine Server Core has a SQL Injection Vulnerability

2024-06-1215:31:45
CWE-89
GitHub Advisory Database
github.com
5
apache submarine server
sql injection
vulnerability
security issue
retired project
unsupported software

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0

Percentile

15.5%

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Apache Submarine Server Core.

This issue affects Apache Submarine Server Core: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected configurations

Vulners
Node
org.apache.submarinesubmarine-server-coreRange0.8.0
VendorProductVersionCPE
org.apache.submarinesubmarine-server-core*cpe:2.3:a:org.apache.submarine:submarine-server-core:*:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0

Percentile

15.5%

Related for GHSA-V74C-QC46-9GG9