Apache warns of critical flaws in MINA, HugeGraph, Traffic Control
ID: ca572fc0-9fba-5ec0-b91b-628e9baacc79
STIX ID: report--ca572fc0-9fba-5ec0-b91b-628e9baacc79
Feed Name: Bleeping Computer
The Apache Software Foundation released urgent security updates for three critical vulnerabilities affecting Apache MINA (CVE-2024-52046 — unsafe Java deserialization potentially enabling RCE, fixed in MINA 2.0.27/2.1.10/2.2.4 with additional configuration required), Apache HugeGraph-Server (CVE-2024-43441 — authentication bypass, fixed in HugeGraph-Server 1.5.0), and Apache Traffic Control/Traffic Ops (CVE-2024-45387 — SQL injection, fixed in Traffic Control 8.0.2); system administrators are strongly advised to upgrade and apply recommended mitigations immediately, especially given high severity scores and increased exploitation risk during holiday periods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
