Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
The vulnerability exists because the authentication mechanism relies on data that is treated as immutable, but can actually be modified by an attacker. By manipulating this data, an attacker can bypass identity verification and gain access to the system without providing valid credentials. The attack requires no user interaction or prior privileges and can be carried out remotely over the network.
An attacker can gain full, unauthorized access to Apache HugeGraph-Server, leading to violations of data and service confidentiality, integrity, and availability. In practice, this means the ability to read, modify, or delete graph data and potential takeover of system control.
Apache HugeGraph-Server must be urgently updated to version 1.5.0, which contains a patch eliminating the described vulnerability.
Apache HugeGraph-Server versions 1.0.0 to 1.4.x (before 1.5.0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Hugegraph
APPApache1.0.0 – 1.5.0 (excl.)
Related vulnerabilities
RCE w Apache HugeGraph-Server — zdalne wykonanie poleceń bez uwierzytelnienia
Pominięcie uwierzytelnienia przez spoofing w Apache HugeGraph-Server
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserial...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację