Apache warns of critical flaws in MINA, HugeGraph, Traffic Control

Share:

The Apache Software Foundation has released security updates to address three severe problems that affect MINA, HugeGraph-Server, and Traffic Control products.

The vulnerabilities were patched in new software versions released between December 23 and 25. However, the holiday period may lead to a slower patching rate and increased risk of exploitation.

One of the bugs is tracked as CVE-2024-52046 and impacts MINA versions 2.0 through 2.0.26, 2.1 through 2.1.9, and 2.2 through 2.2.3. The issue received a critical severity score of 10 out of 10 from the Apache Software Foundation

Apache MINA is a network application framework that provides an abstraction layer for developing high-performance and scalable network applications.

The latest problem lies in ‘ObjectSerializationDecoder’ caused by unsafe Java deserialization, potentially leading to remote code execution (RCE).

The Apache team clarified that the vulnerability is exploitable if the ‘IoBuffer#getObject()’ method is used in combination with certain classes.

Apache addressed the issue with the release of versions 2.0.27, 2.1.10, and 2.2.4, which enhanced the vulnerable component with stricter security defaults.

However, upgrading to those versions isn’t enough. Users also need to manually set the rejection of all classes unless explicitly allowed by following one of the three methods provided.

The vulnerability impacting Apache HugeGraph-Server versions 1.0 through 1.3, is an authentication bypass problem tracked as CVE-2024-43441. It is caused by improper validation of authentication logic.

Apache HugeGraph-Server is a graph database server that enables efficient storage, querying, and analysis of graph-based data.

The authentication bypass problem was addressed in version 1.5.0, which is the recommended upgrade target for HugeGraph-Server users.

The third flaw is identified as CVE-2024-45387 and the Apache Software Foundation rated it with a 9.9 critical severity score. It is an SQL injection problem impacting Traffic Ops versions 8.0.0 to 8.0.1.

Apache Traffic Control is a Content Delivery Network (CDN) management and optimization tool.

The latest problem on the product is caused by the insufficient input sanitization of SQL queries, allowing arbitrary SQL command execution using specially crafted PUT requests.

The problem was fixed in Apache Traffic Control version 8.0.2, released earlier this week. The Apache team noted that versions 7.0.0 to up to 8.0.0 are not impacted.

System administrators are strongly recommended to upgrade to the latest product version as soon as possible, especially as hackers often choose to strike during this time of the year when companies have fewer employees on duty and response times are longer.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:48 pm, Jan 17, 2025
weather icon 4°C
L: 3° | H: 5°
overcast clouds
Humidity: 86 %
Pressure: 1035 mb
Wind: 5 mph S
Wind Gust: 18 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:57 am
Sunset: 4:23 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
3° | 5°°C 0 mm 0% 3 mph 86 % 1035 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 91 % 1035 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
1° | 6°°C 0 mm 0% 6 mph 90 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 92 % 1020 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 5 mph 95 % 1019 mb 0 mm/h
Today 9:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 86 % 1035 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 4°°C 0 mm 0% 3 mph 87 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 3°°C 0 mm 0% 2 mph 88 % 1033 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 2°°C 0 mm 0% 1 mph 91 % 1031 mb 0 mm/h
Tomorrow 9:00 am
weather icon
2° | 2°°C 0 mm 0% 2 mph 87 % 1031 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 67 % 1030 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 3 mph 61 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 81 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€102,016.71
4.53%
Ethereum(ETH)
€3,407.51
5.25%
XRP(XRP)
€3.17
-1.47%
Tether(USDT)
€0.97
0.05%
Solana(SOL)
€213.22
2.84%
Dogecoin(DOGE)
€0.404425
8.38%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000023
9.07%
Pepe(PEPE)
€0.000019
10.79%
Peanut the Squirrel(PNUT)
€0.64
7.37%
Scroll to Top