logo

Critical Apache HugeGraph Vulnerability Under Attack - Patch ASAP

ID: 12e0c2bf-3e9e-59cd-81a0-8304f93cac20

STIX ID: report--12e0c2bf-3e9e-59cd-81a0-8304f93cac20

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-07-17

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

A critical remote code execution vulnerability (CVE-2024-27348, CVSS 9.8) in Apache HugeGraph-Server's Gremlin API affects all versions prior to 1.3.0. SecureLayer7 reported the flaw allows sandbox bypass and full server code execution, proof-of-concept code is public, and the Shadowserver Foundation has observed active exploitation attempts; administrators are urged to upgrade to HugeGraph 1.3.0 with Java 11 and enable authentication and IP/port whitelisting immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.