PT-2024-10202 · Apache · Apache Hugegraph-Server

·

CVE-2024-43441

·

Published

2024-08-13

·

Updated

2026-02-16

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HugeGraph-Server versions 1.0.0 through 1.5.0
Description The issue is related to an authentication bypass vulnerability in Apache HugeGraph-Server, which can be exploited by remote attackers to execute arbitrary code. This vulnerability is caused by the exploitation of assumed-immutable data.
Recommendations To resolve the issue, users are recommended to upgrade to version 1.5.0, which fixes the issue. As a temporary workaround, consider restricting access to sensitive graph data until the upgrade is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00531
CVE-2024-43441
GHSA-F697-GM3H-XRF9

Affected Products

Apache Hugegraph-Server