CRITICAL

CVE-2024-27348

Apache Hugegraph 2024-04-22 CVSS v3.1
CVSS
9.8
KEV

Description

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11

Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

Summary dbcve.org

Apache HugeGraph-Server versions 1.0.0 through versions before 1.3.0 contain a critical Remote Command Execution (RCE) vulnerability allowing unauthenticated attackers to execute arbitrary commands on the server. The vulnerability is present in both Java8 and Java11 environments. Successful exploitation gives the attacker full control over the server hosting the graph database.

Mitigation

Upgrade Apache HugeGraph-Server to version 1.3.0 or later and migrate to Java11 if not already done. Additionally, enable the built-in Authentication system to provide defense-in-depth protection against this and other attack vectors.

Proof of Concept

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

99.21%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE