GHSA-29rc-vq7f-x335

Source
https://github.com/advisories/GHSA-29rc-vq7f-x335
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-29rc-vq7f-x335/GHSA-29rc-vq7f-x335.json
Aliases
  • CVE-2024-27348
Published
2024-04-22T15:30:41Z
Modified
2024-05-02T15:01:17.891153Z
Details

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11

Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

References

Affected packages

Maven / org.apache.hugegraph:hugegraph-api

Package

Name
org.apache.hugegraph:hugegraph-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.3.0

Affected versions

1.*

1.0.0
1.2.0

Maven / org.apache.hugegraph:hugegraph-core

Package

Name
org.apache.hugegraph:hugegraph-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.3.0

Affected versions

1.*

1.0.0
1.2.0