Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
The vulnerability classified as CWE-290 (Authentication Bypass by Spoofing) occurs because the server's authentication mechanism can be bypassed by forging (spoofing) appropriate request elements. An attacker sends a crafted network request, which the system incorrectly treats as authenticated. No user interaction or possession of any account privileges is required.
An attacker can gain unauthorized access to sensitive data and the ability to modify resources managed by Apache HugeGraph-Server, which translates to high risk of data confidentiality and integrity violations.
Apache HugeGraph-Server should be updated to version 1.3.0 or newer, which contains a fix that eliminates this vulnerability.
Apache HugeGraph-Server in versions from 1.0.0 to below 1.3.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Hugegraph
APPApache1.0.0 – 1.3.0 (excl.)
Related vulnerabilities
RCE w Apache HugeGraph-Server — zdalne wykonanie poleceń bez uwierzytelnienia
Authentication Bypass w Apache HugeGraph-Server (zakładane niezmienne dane)
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację