RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
The vulnerability results from insufficient access control (CWE-284) in Apache HugeGraph-Server running on Java 8 or Java 11 in versions from 1.0.0 to 1.3.0. An attacker can send a specially crafted network request to the server without any authentication, which leads to execution of arbitrary commands in the context of the server process. The lack of user interaction requirement and the lack of need for any privileges makes this attack vector particularly dangerous.
An attacker gains full control over the system — it is possible to read, modify or delete data, as well as take control of the server and further penetrate the infrastructure (lateral movement).
Apache HugeGraph-Server must be urgently updated to version 1.3.0 running on Java 11 and the authentication system (Auth system) must be enabled according to the vendor's documentation available at: https://hugegraph.apache.org/docs/config/config-authentication/
Apache HugeGraph-Server in versions from 1.0.0 to 1.3.0 (inclusive) running on Java 8 and Java 11
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Hugegraph
APPApache1.0.0 – 1.3.0 (excl.)
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- HugeGraph-Server
- Added to KEVi
- September 18, 2024
- Remediation deadline (US Federal)i
- October 9, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
Related vulnerabilities
Authentication Bypass w Apache HugeGraph-Server (zakładane niezmienne dane)
Pominięcie uwierzytelnienia przez spoofing w Apache HugeGraph-Server
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację