CVE-2024-27348
KEV PoC niche1Unauthenticated RCE in Apache HugeGraph-Server 1.0.0-1.2.x
CISA: Apache HugeGraph-Server Improper Access Control Vulnerability
Apache HugeGraph-Server versions 1.0.0 through versions before 1.3.0 contain an improper access control flaw (CWE-284) that enables unauthenticated remote code execution through the server's network-facing API when the authentication system is not enabled. An attacker with network access to a vulnerable server can send crafted requests that execute arbitrary commands on the host with no credentials, privileges, or user interaction required, consistent with the CVSS 9.8 network/low-complexity vector. All deployments of HugeGraph-Server 1.0.0-1.2.x running on Java 8 or Java 11 are affected, especially instances exposed to untrusted networks with auth disabled. Exploitation is active: the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-18, public reporting says it is under attack, and EPSS assigns a 99.2% probability of exploitation within 30 days (100th percentile). CISA's required action is to apply vendor mitigations per vendor instructions or discontinue use of the product.
What to do: Upgrade to Apache HugeGraph-Server 1.3.0 running on Java 11 and enable the authentication (Auth) system, which fixes the issue per the vendor. If upgrading is not immediately possible, restrict network access to the HugeGraph-Server API to trusted clients and enable auth, and audit internet-exposed instances for signs of exploitation. Because this flaw is in CISA's KEV catalog, federal agencies and other bound organizations must apply the vendor mitigations or discontinue use by the required deadline.
| Apache HugeGraph-Server | from 1.0.0 before 1.3.0 (running on Java 8 or Java 11) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
- Affected
- Apache HugeGraph-Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apache
- Products
- hugegraph
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H