GHSA-v5gj-fx3g-hcpw · Severity: critical · Ecosystem: pip — SQL injection in Apache Submarine
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from 0.7.0 before 0.8.0. We recommend that all submarine users with 0.7.0 upgrade to 0.8.0, which not only fixes the issue, supports the oidc authentication mode, but also removes the case of unauthenticated logins. If using the version lower than 0.8.0 and not want to upgrade, you can try cherry-pick PR https://github.com/apache/submarine/pull/1037 https://github.com/apache/submarine/pull/1054 and rebuild the submarine-server image to fix this.
Conclusion & alert: CVE-2023-37924 is rated High Risk (72/100): CVSS Critical severity, with high exploitation likelihood (EPSS 77.07%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 78.90% | 77.07% | -1.83% |
| 2 | 2025-11-18 | 77.07% | 78.90% | +1.83% |
| 3 | 2025-04-15 | — | 77.07% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-v5gj-fx3g-hcpw · Severity: critical · Ecosystem: pip — SQL injection in Apache Submarine
| URL | Tags |
|---|---|
| https://github.com/apache/submarine/pull/1037 | Issue Tracking |
| https://issues.apache.org/jira/browse/SUBMARINE-1361 | Issue Tracking Vendor Advisory |
| https://lists.apache.org/thread/g99h773vd49n1wyghdq1llv2f83w1b3r | Mailing List Vendor Advisory |