logo

Apache warns of critical flaws in MINA, HugeGraph, Traffic Control

ID: ca572fc0-9fba-5ec0-b91b-628e9baacc79

STIX ID: report--ca572fc0-9fba-5ec0-b91b-628e9baacc79

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-26

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The Apache Software Foundation released urgent security updates for three critical vulnerabilities affecting Apache MINA (CVE-2024-52046 — unsafe Java deserialization potentially enabling RCE, fixed in MINA 2.0.27/2.1.10/2.2.4 with additional configuration required), Apache HugeGraph-Server (CVE-2024-43441 — authentication bypass, fixed in HugeGraph-Server 1.5.0), and Apache Traffic Control/Traffic Ops (CVE-2024-45387 — SQL injection, fixed in Traffic Control 8.0.2); system administrators are strongly advised to upgrade and apply recommended mitigations immediately, especially given high severity scores and increased exploitation risk during holiday periods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.