Apache warns of critical flaws in MINA, HugeGraph, Traffic Control

Share:

The Apache Software Foundation has released security updates to address three severe problems that affect MINA, HugeGraph-Server, and Traffic Control products.

The vulnerabilities were patched in new software versions released between December 23 and 25. However, the holiday period may lead to a slower patching rate and increased risk of exploitation.

One of the bugs is tracked as CVE-2024-52046 and impacts MINA versions 2.0 through 2.0.26, 2.1 through 2.1.9, and 2.2 through 2.2.3. The issue received a critical severity score of 10 out of 10 from the Apache Software Foundation

Apache MINA is a network application framework that provides an abstraction layer for developing high-performance and scalable network applications.

The latest problem lies in ‘ObjectSerializationDecoder’ caused by unsafe Java deserialization, potentially leading to remote code execution (RCE).

The Apache team clarified that the vulnerability is exploitable if the ‘IoBuffer#getObject()’ method is used in combination with certain classes.

Apache addressed the issue with the release of versions 2.0.27, 2.1.10, and 2.2.4, which enhanced the vulnerable component with stricter security defaults.

However, upgrading to those versions isn’t enough. Users also need to manually set the rejection of all classes unless explicitly allowed by following one of the three methods provided.

The vulnerability impacting Apache HugeGraph-Server versions 1.0 through 1.3, is an authentication bypass problem tracked as CVE-2024-43441. It is caused by improper validation of authentication logic.

Apache HugeGraph-Server is a graph database server that enables efficient storage, querying, and analysis of graph-based data.

The authentication bypass problem was addressed in version 1.5.0, which is the recommended upgrade target for HugeGraph-Server users.

The third flaw is identified as CVE-2024-45387 and the Apache Software Foundation rated it with a 9.9 critical severity score. It is an SQL injection problem impacting Traffic Ops versions 8.0.0 to 8.0.1.

Apache Traffic Control is a Content Delivery Network (CDN) management and optimization tool.

The latest problem on the product is caused by the insufficient input sanitization of SQL queries, allowing arbitrary SQL command execution using specially crafted PUT requests.

The problem was fixed in Apache Traffic Control version 8.0.2, released earlier this week. The Apache team noted that versions 7.0.0 to up to 8.0.0 are not impacted.

System administrators are strongly recommended to upgrade to the latest product version as soon as possible, especially as hackers often choose to strike during this time of the year when companies have fewer employees on duty and response times are longer.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:46 pm, Apr 21, 2025
weather icon 10°C
L: 9° | H: 11°
scattered clouds
Humidity: 85 %
Pressure: 1013 mb
Wind: 10 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 30%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:51 am
Sunset: 8:06 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
9° | 11°°C 0 mm 0% 12 mph 91 % 1017 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
9° | 15°°C 1 mm 100% 16 mph 96 % 1016 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
8° | 15°°C 0 mm 0% 8 mph 90 % 1021 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
9° | 15°°C 0.4 mm 40% 8 mph 89 % 1021 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
10° | 13°°C 1 mm 100% 11 mph 95 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
9° | 10°°C 0 mm 0% 6 mph 87 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 9°°C 0 mm 0% 4 mph 91 % 1014 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 0 mm 0% 4 mph 91 % 1016 mb 0 mm/h
Tomorrow 10:00 am
weather icon
13° | 13°°C 0 mm 0% 6 mph 68 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
16° | 16°°C 0 mm 0% 8 mph 42 % 1017 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 36 % 1016 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
13° | 13°°C 0 mm 0% 12 mph 57 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 10°°C 0 mm 0% 9 mph 74 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€75,680.92
2.51%
Ethereum(ETH)
€1,368.66
-0.72%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.80
0.05%
Solana(SOL)
€118.51
-0.50%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.137443
1.65%
Shiba Inu(SHIB)
€0.000010
-0.29%
Pepe(PEPE)
€0.000007
2.49%
Scroll to Top