By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: CISA warns of actively exploited Apache HugeGraph-Server bug
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > CISA warns of actively exploited Apache HugeGraph-Server bug
Tech News

CISA warns of actively exploited Apache HugeGraph-Server bug

By admin 3 Min Read
Share
SHARE

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server.

The flaw, tracked as CVE-2024-27348 and rated critical (CVSS v3.1 score: 9.8), is an improper access control vulnerability that impacts HugeGraph-Server versions from 1.0.0 and up to, but not including 1.3.0.

Apache fixed the vulnerability on April 22, 2024, with the release of version 1.3.0. Apart from upgrading to the latest version, users were also recommended to use Java 11 and enable the Auth system.

Also, enabling the “Whitelist-IP/port” function was proposed to improve the security of the RESTful-API execution, which was involved in potential attack chains.

Now, CISA has warned that active exploitation of CVE-2024-27348 has been observed in the wild, giving federal agencies and other critical infrastructure organizations until October 9, 2024, to apply mitigations or discontinue the use of the product.

Apache HugeGraph-Server is the core component of the Apache HugeGraph project, an open-source graph database designed for handling large-scale graph data with high performance and scalability, supporting complex operations required in deep relationship exploitation, data clustering, and path searches.

The product is used, among others, by telecom providers for fraud detection and network analysis, financial services for risk control and transaction pattern analysis, and social networks for connection analysis and automated recommendation systems.

With active exploitation underway and the product used in apparently high-value enterprise environments, applying the available security updates and mitigations as soon as possible is exigent.

The other four flaws added to KEV this time are:

  • CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
  • CVE-2019-1069: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
  • CVE-2022-21445: Oracle JDeveloper Remote Code Execution Vulnerability
  • CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

The inclusion of these older vulnerabilities is not an indication of recent exploitation but serves to enrich the KEV catalog by documenting security flaws that were confirmed to have been used in attacks at some point in the past.

You Might Also Like

iMP Tech Mini Arcade Pro Review: A Nintendo Switch Arcade Cabinet

Defence and Security vulnerabilities critical issue for business – Ibec

Cisco Premier Provider Worldwide Status for Viatel Technology Group

Why Pet-Focused Air Purification Is Becoming a Smart-Home Essential

MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

TAGGED: Actively Exploited, Apache, CISA, RCE, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Israel Destroys 1,000 Hezbollah Rocket Launcher Barrels, Says Military
Next Article 15 people selected for new UCD-Teagasc agrifood programme
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Denargo Market to open beer garden in 2026
Business
iMP Tech Mini Arcade Pro Review: A Nintendo Switch Arcade Cabinet
Tech News
Polkadot price forecast: market weakness hinders bulls near 1.90
Crypto
The hidden impact of domestic cats on wildlife revealed by social media
World News
Pundit Shares ‘Urgent Update’ With XRP Community – Here’s What He Said
Crypto
Gillingham fans have last laugh after being told to ‘sit down’ by Cambridge’s Pelly Ruddock Mpanzu
Sports
Defence and Security vulnerabilities critical issue for business – Ibec
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Denargo Market to open beer garden in 2026

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Denargo Market to open beer garden in 2026
December 29, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?