CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-27348

CVSS 9.8v3.1pub. 2024-04-22upd. 2025-10-23

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability results from insufficient access control (CWE-284) in Apache HugeGraph-Server running on Java 8 or Java 11 in versions from 1.0.0 to 1.3.0. An attacker can send a specially crafted network request to the server without any authentication, which leads to execution of arbitrary commands in the context of the server process. The lack of user interaction requirement and the lack of need for any privileges makes this attack vector particularly dangerous.

Impact

An attacker gains full control over the system — it is possible to read, modify or delete data, as well as take control of the server and further penetrate the infrastructure (lateral movement).

Mitigation & patch

Apache HugeGraph-Server must be urgently updated to version 1.3.0 running on Java 11 and the authentication system (Auth system) must be enabled according to the vendor's documentation available at: https://hugegraph.apache.org/docs/config/config-authentication/

Who is affected

Apache HugeGraph-Server in versions from 1.0.0 to 1.3.0 (inclusive) running on Java 8 and Java 11

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Hugegraph

    APP
    Apache
    1.0.0 – 1.3.0 (excl.)

CISA KEV — detailsi

Vendori
Apache
Producti
HugeGraph-Server
Added to KEVi
September 18, 2024
Remediation deadline (US Federal)i
October 9, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 9 października 2024
CWE
References

Related vulnerabilities

CVE-2024-43441CRITICAL9.8PL ✓same product

Authentication Bypass w Apache HugeGraph-Server (zakładane niezmienne dane)

CVE-2024-27349CRITICAL9.1PL ✓same product

Pominięcie uwierzytelnienia przez spoofing w Apache HugeGraph-Server

CVE-2025-26866HIGH8.8same product

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same vendor

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację