One of the five vulnerabilities that the U.S. Cybersecurity and Infrastructure Agency (CISA) has added to its catalog of known exploited vulnerabilities (KEV) affects Apache HugeGraph-Server and involves remote code execution (RCE).
HugeGraph-Server versions 1.0.0 and up to, but excluding 1.3.0, are affected by the incorrect access control vulnerability, tracked as CVE-2024-27348 and graded critical (CVSS v3.1 score: 9.8).
Version 1.3.0 of Apache was released on April 22, 2024, which addressed the issue. In addition to updating to the most recent version, users were advised to activate the Auth system and utilize Java 11.
Additionally, it was suggested to activate the “Whitelist-IP/port” function to strengthen the security of the RESTful-API execution, which was implicated in possible attack chains read more about CISA warns of actively exploited Apache HugeGraph-Server bug.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions
