CRITICAL🇵🇱 Wersja polska

CVE-2024-43441

CVSS 9.8v3.1pub. 2024-12-24upd. 2025-07-01

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability exists because the authentication mechanism relies on data that is treated as immutable, but can actually be modified by an attacker. By manipulating this data, an attacker can bypass identity verification and gain access to the system without providing valid credentials. The attack requires no user interaction or prior privileges and can be carried out remotely over the network.

Impact

An attacker can gain full, unauthorized access to Apache HugeGraph-Server, leading to violations of data and service confidentiality, integrity, and availability. In practice, this means the ability to read, modify, or delete graph data and potential takeover of system control.

Mitigation & patch

Apache HugeGraph-Server must be urgently updated to version 1.5.0, which contains a patch eliminating the described vulnerability.

Who is affected

Apache HugeGraph-Server versions 1.0.0 to 1.4.x (before 1.5.0)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Hugegraph

    APP
    Apache
    1.0.0 – 1.5.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-27348CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache HugeGraph-Server — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2024-27349CRITICAL9.1PL ✓same product

Pominięcie uwierzytelnienia przez spoofing w Apache HugeGraph-Server

CVE-2025-26866HIGH8.8same product

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same vendor

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację