Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47507
HistoryJun 13, 2024 - 5:43 a.m.

Improper Authentication

2024-06-1305:43:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1
authentication
json web token
submarineconfvars

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

org.apache.submarine:submarine-commons-utils is vulnerable to Improper Authentication. The vulnerability is caused by a hard-coded JSON Web Token (JWT) key (SUBMARINE_SECRET_12345678901234567890) within SubmarineConfVars.java, which allows attackers to generate unauthorized JWT tokens, bypass authentication, and potentially gain access to sensitive data and functionality.

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%