Apache Submarine (Submarine for short) is an End-to-End Machine Learning Platform to allow data scientists to create end-to-end machine learning workflows. On Submarine, data scientists can finish each stage in the ML model lifecycle, including data exploration, data pipeline creation, model training, serving, and monitoring.
Apache Submarine (retired to the Apache Attic) suffers from an authentication bypass leading to unauthenticated remote code execution. The security filter CommonFilter.isProtectedApi() treats any request whose User-Agent header matches the Python SDK pattern as not requiring authentication, and the User-Agent header is fully attacker-controlled, so any client that sets that header reaches every protected REST endpoint with no token. Through the experiment API an attacker can define the container image and command of a job, which are placed directly onto the launched Kubernetes pod, resulting in unauthenticated remote code execution on the cluster and full administrative takeover via the user-management APIs.