CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
Other sources
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.hugegraph:hugegraph-coreto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
maven/org.apache.hugegraph:hugegraph-apito a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
Apache HugeGraph-Serverto a version that resolves this vulnerability.Fixed in 1.3.0 - Configuration
Enable the Auth system in Apache HugeGraph-Server
Apache HugeGraph-Server Auth system = enabled - Configuration
Run Apache HugeGraph-Server on Java11
Java runtime Java version = Java11
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27348?
CVE-2024-27348 is classified as a critical vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2024-27348?
To remediate CVE-2024-27348, upgrade Apache HugeGraph from any version prior to 1.3.0 to version 1.3.0 or later.
Which versions of Apache HugeGraph are affected by CVE-2024-27348?
CVE-2024-27348 affects Apache HugeGraph versions from 1.0.0 up to, but not including, 1.3.0.
Can CVE-2024-27348 lead to data compromise?
Yes, CVE-2024-27348 can lead to data compromise by allowing attackers to execute arbitrary code remotely.
Is there a workaround for CVE-2024-27348 before upgrading?
Currently, the recommended approach is to upgrade to version 1.3.0 to mitigate the risk posed by CVE-2024-27348.