Apache HugeGraph-Server: Command execution in gremlin
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 9.8epss 99%
de la publicación al arma39 días
Publicada en NVD22 abr
1ª PoC+39d
metasploit22 abr
CISA KEV+149d
probabilidad de explotación
99%top 1% de las CVE
explotación observada
síCISA + VulnCheck
13 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2024-10-09
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache HugeGraph-ServerPoCs públicas encontradas — 13
exploitdbwww.exploit-db.com/exploits/52149no verificadogithubgithub.com/Zeyad-Azima/CVE-2024-27348★ 61githubgithub.com/kljunowsky/CVE-2024-27348★ 19githubgithub.com/jakabakos/CVE-2024-27348-Apache-HugeGraph-RCE★ 4githubgithub.com/akelaqe/CVE-2024-27348-HugeGraph-RCE★ 1githubgithub.com/wqfh/CVE-2024-27348★ 1githubgithub.com/p0et08/CVE-2024-27348★ 0vulncheckvulncheck.com/xdb/1e027cb9ed60no verificadovulncheckvulncheck.com/xdb/cbdb064daf5fno verificadovulncheckvulncheck.com/xdb/6e2e43534884no verificadovulncheckvulncheck.com/xdb/74d386417a3eno verificadovulncheckvulncheck.com/xdb/486eb74db84bno verificadovulncheckvulncheck.com/xdb/0817f891a615no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authenticationhttps://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27348https://www.vicarius.io/vsociety/posts/remote-code-execution-vulnerability-in-apache-hugegraph-server-cve-2024-27348http://www.openwall.com/lists/oss-security/2024/04/22/3