logo

POC exploit code published for 9.8-rated Apache HugeGraph RCE flaw

ID: dbde149a-7739-5c66-97f2-fbcb6da84b69

STIX ID: report--dbde149a-7739-5c66-97f2-fbcb6da84b69

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-06-07

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical RCE vulnerability (CVE-2024-27348, CVSS 9.8) affecting Apache HugeGraph-Server prior to v1.3.0 can bypass sandboxing via crafted Gremlin commands; public proof-of-concept exploits and a Python scanner are available on GitHub, increasing the risk of widespread abuse. Administrators are urged to upgrade to 1.3.0 with Java 11 and enable authentication and IP/port whitelisting immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.