vendor:
HugeGraph Server
by:
Yesith Alvarez
6.1
CVSS
HIGH
Remote Code Execution (RCE)
RCE
CWE
Product Name: HugeGraph Server
Affected Version From: 1.0.0
Affected Version To: 1.2.2000
Patch Exists: NO
Related CWE: CVE-2024-27348
CPE: a:apache:hugegraph_server:1.2.0
Platforms Tested:
2024
Apache HugeGraph Server 1.2.0 – Remote Code Execution (RCE)
The Apache HugeGraph Server version 1.2.0 and prior is vulnerable to remote code execution. By sending a crafted payload to the server, an attacker can execute arbitrary code on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update Apache HugeGraph Server to a patched version (if available) and restrict network access to the server.