VDB
Sign up
CRITICAL9.8

GHSA-29rc-vq7f-x335

Apache HugeGraph-Server: Command execution in gremlin

Quick fix

GHSA-29rc-vq7f-x335 — org.apache.hugegraph:hugegraph-api: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.3.0</version> for org.apache.hugegraph:hugegraph-api

Details

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11

Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.hugegraph:hugegraph-api
Introduced in: 1.0.0Fixed in: 1.3.0
Fix# pom.xml: bump <version>1.3.0</version> for org.apache.hugegraph:hugegraph-api
Maven/org.apache.hugegraph:hugegraph-core
Introduced in: 1.0.0Fixed in: 1.3.0
Fix# pom.xml: bump <version>1.3.0</version> for org.apache.hugegraph:hugegraph-core

References