CISA warns of actively exploited Apache HugeGraph-Server bug

Teilen:

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server.

The flaw, tracked as CVE-2024-27348 and rated critical (CVSS v3.1 score: 9.8), is an improper access control vulnerability that impacts HugeGraph-Server versions from 1.0.0 and up to, but not including 1.3.0.

Apache fixed the vulnerability on April 22, 2024, with the release of version 1.3.0. Apart from upgrading to the latest version, users were also recommended to use Java 11 and enable the Auth system.

Also, enabling the “Whitelist-IP/port” function was proposed to improve the security of the RESTful-API execution, which was involved in potential attack chains.

Now, CISA has warned that active exploitation of CVE-2024-27348 has been observed in the wild, giving federal agencies and other critical infrastructure organizations until October 9, 2024, to apply mitigations or discontinue the use of the product.

Apache HugeGraph-Server is the core component of the Apache HugeGraph project, an open-source graph database designed for handling large-scale graph data with high performance and scalability, supporting complex operations required in deep relationship exploitation, data clustering, and path searches.

The product is used, among others, by telecom providers for fraud detection and network analysis, financial services for risk control and transaction pattern analysis, and social networks for connection analysis and automated recommendation systems.

With active exploitation underway and the product used in apparently high-value enterprise environments, applying the available security updates and mitigations as soon as possible is exigent.

The other four flaws added to KEV this time are:

  • CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
  • CVE-2019-1069: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
  • CVE-2022-21445: Oracle JDeveloper Remote Code Execution Vulnerability
  • CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

The inclusion of these older vulnerabilities is not an indication of recent exploitation but serves to enrich the KEV catalog by documenting security flaws that were confirmed to have been used in attacks at some point in the past.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:55 am, Jan. 26, 2025
Wetter-Symbol 3°C
L: 2° | H: 3°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1004 mb
Wind: 7 mph SE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:47 am
Sonnenuntergang: 4:38 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
2° | 3°°C 1 mm 100% 20 mph 90 % 1004 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 22 mph 90 % 984 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
7° | 9°°C 1 mm 100% 21 mph 86 % 996 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 7°°C 1 mm 100% 15 mph 93 % 1001 mb 0 mm/h
Do. Jan. 30 9:00 pm
Wetter-Symbol
3° | 6°°C 0.93 mm 93% 10 mph 95 % 1023 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 9 mph 81 % 1004 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
4° | 5°°C 0 mm 0% 14 mph 82 % 1003 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0.23 mm 23% 18 mph 81 % 999 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 1 mm 100% 20 mph 90 % 989 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 14 mph 84 % 988 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 16 mph 79 % 986 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 20 mph 90 % 979 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
7° | 7°°C 1 mm 100% 14 mph 77 % 982 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,135.18
0.78%
Ethereum(ETH)
€3,185.95
1.51%
XRP(XRP)
€2.98
0.82%
Fesseln(USDT)
€0.95
-0.01%
Solana(SOL)
€245.99
3.61%
Dogecoin(DOGE)
€0.337870
1.39%
USDC(USDC)
€0.95
-0.01%
Shiba Inu(SHIB)
€0.000019
0.34%
Pepe(PEPE)
€0.000014
0.21%
Peanut das Eichhörnchen(PNUT)
€0.341643
3.03%
Nach oben scrollen