RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27348
https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9
https://github.com/wqfh/MasterOfTheIndestry
https://github.com/ismailmazumder/SL7CVELabsBuilder
https://github.com/securelayer7/SL7CVELabsBuilder
https://github.com/p0et08/CVE-2024-27348
https://github.com/whitehacklabs/CVE
https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication
Published: 2024-04-22
Updated: 2025-10-23
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.9921
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored