CVE-2024-36263
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
12/06/2024
Last modified:
15/07/2025
Description
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command (&#39;SQL Injection&#39;) vulnerability in Apache Submarine Server Core.<br />
<br />
This issue affects Apache Submarine Server Core: all versions.<br />
<br />
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.<br />
<br />
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:submarine:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2024/06/12/1
- https://github.com/apache/submarine/pull/1121
- https://lists.apache.org/thread/8q9kbdg9gk9kpz5p8x6t7q8709l3vrmt
- http://www.openwall.com/lists/oss-security/2024/06/12/1
- https://github.com/apache/submarine/pull/1121
- https://lists.apache.org/thread/8q9kbdg9gk9kpz5p8x6t7q8709l3vrmt



