Home ยป Database

AVID-2026-R1489

Description

Apache Submarine Server Core: authorization bypass (CVE-2024-36265)

Details

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.

This issue affects Apache Submarine Server Core: from 0.8.0.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Reason for inclusion in AVID: CVE-2024-36265 is an incorrect authorization vulnerability in Apache Submarine Server Core, an ML/AI platform component. It concerns software used in AI pipelines, is a security vulnerability (CWE-863), and affects components used to build/deploy AI systems. The CVE provides evidence (NVD entry and references). Although the project is retired and no fix is planned, it remains a software supply chain risk signal for AI systems relying on this component.

References

Affected or Relevant Artifacts

  • Developer: Apache Software Foundation
  • Deployer: Apache Software Foundation
  • Artifact Details:
TypeName
SystemApache Submarine Server Core

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CWE

IDDescription
CWE-863CWE-863 Incorrect Authorization

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-06-12
  • Version: 0.3.3
  • AVID Entry