CRITICAL🇵🇱 Wersja polska

CVE-2024-27349

CVSS 9.1v3.1pub. 2024-04-22upd. 2025-06-30

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-290 (Authentication Bypass by Spoofing) occurs because the server's authentication mechanism can be bypassed by forging (spoofing) appropriate request elements. An attacker sends a crafted network request, which the system incorrectly treats as authenticated. No user interaction or possession of any account privileges is required.

Impact

An attacker can gain unauthorized access to sensitive data and the ability to modify resources managed by Apache HugeGraph-Server, which translates to high risk of data confidentiality and integrity violations.

Mitigation & patch

Apache HugeGraph-Server should be updated to version 1.3.0 or newer, which contains a fix that eliminates this vulnerability.

Who is affected

Apache HugeGraph-Server in versions from 1.0.0 to below 1.3.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Hugegraph

    APP
    Apache
    1.0.0 – 1.3.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-27348CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache HugeGraph-Server — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2024-43441CRITICAL9.8PL ✓same product

Authentication Bypass w Apache HugeGraph-Server (zakładane niezmienne dane)

CVE-2025-26866HIGH8.8same product

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same vendor

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację