CVE-2024-27348
Last modified
CVE-2024-27348 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.21% chance of exploitation in the next 30 days.
Description
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hugegraph | >= 1.0.0, < 1.3.0 |
References
- https://www.openwall.com/lists/oss-security/2024/04/22/3Mailing List, Third Party Advisory
- https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9Mailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2024/04/22/3Mailing List, Third Party Advisory
- https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9Mailing List, Vendor Advisory
- https://www.vicarius.io/vsociety/posts/remote-code-execution-vulnerability-in-apache-hugegraph-server-cve-2024-27348Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27348Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-27348?
How severe is CVE-2024-27348?
How do I fix CVE-2024-27348?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27342Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote …7.8
- CVE-2024-27343Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Informat…5.5
- CVE-2024-27344Kofax Power PDF PDF File Parsing Memory Corruption Remote Co…7.8
- CVE-2024-27345Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Informat…3.3
- CVE-2024-27346Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Informat…5.5
- CVE-2024-27347Server-Side Request Forgery (SSRF) vulnerability in Apache H…5.3
- CVE-2024-27349Authentication Bypass by Spoofing vulnerability in Apache Hu…9.1
- CVE-2024-2735The Bold Page Builder plugin for WordPress is vulnerable to …5.4
- CVE-2024-27350Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows …5.9
- CVE-2024-27351In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 befo…5.3
- CVE-2024-27353A memory corruption vulnerability in SdHost and SdMmcDevice …7.4
- CVE-2024-27354An issue was discovered in phpseclib 1.x before 1.0.23, 2.x …7.5
Are you affected by CVE-2024-27348?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
