PT-2024-10202 · Apache · Apache Hugegraph-Server
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HugeGraph-Server versions 1.0.0 through 1.5.0
Description
The issue is related to an authentication bypass vulnerability in Apache HugeGraph-Server, which can be exploited by remote attackers to execute arbitrary code. This vulnerability is caused by the exploitation of assumed-immutable data.
Recommendations
To resolve the issue, users are recommended to upgrade to version 1.5.0, which fixes the issue. As a temporary workaround, consider restricting access to sensitive graph data until the upgrade is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Hugegraph-Server