CVE-2024-27348

critical

Description

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

References

https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9

https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication

http://www.openwall.com/lists/oss-security/2024/04/22/3

Details

Source: Mitre, NVD

Published: 2024-04-22

Updated: 2024-05-01

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical