S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 2, 2024

CVE-2024-27348 Scanner

CVE-2024-27348 scanner - Remote Code Execution (RCE) vulnerability in Apache HugeGraph-Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-27348
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache HugeGraph-Serverby Apache Software Foundation
AFFECTED< 1.3.0SAFE ✓≥ 1.3.0
hugegraph-serverby apache
AFFECTED< 1.3.0SAFE ✓≥ 1.3.0
Updated Aug 22, 2026View on NVD →
Detail

Apache HugeGraph-Server is an open-source graph database designed for managing and analyzing large-scale graph data. It is widely used by organizations requiring high-performance graph data solutions. HugeGraph-Server supports environments running Java8 and Java11. The software is often implemented in complex data analysis and storage systems, providing scalable and efficient graph database management.

The vulnerability CVE-2024-27348 allows Remote Code Execution (RCE) within the Apache HugeGraph-Server. Specifically, it affects versions prior to 1.3.0, compromising the security of the system. This vulnerability enables attackers to execute arbitrary commands remotely through the gremlin component. Proper mitigations should be implemented to secure the affected systems.

The Remote Code Execution vulnerability in Apache HugeGraph-Server is found within the gremlin component. It allows an attacker to execute arbitrary commands by exploiting a specific endpoint with crafted input data. The vulnerable parameter involves manipulating Java objects via reflection. This could potentially enable unauthorized actions on the server by sending a specially crafted POST request to the gremlin endpoint.

Exploitation of this vulnerability can lead to complete compromise of the affected server. Attackers could execute arbitrary commands, resulting in unauthorized access to sensitive data, disruption of services, and further network infiltration. The severity of this vulnerability is critical as it allows remote execution of commands without any prior authentication.

Join the S4E platform to safeguard your digital assets effectively. With our comprehensive scanning tools, you can identify and mitigate vulnerabilities like the CVE-2024-27348 RCE in Apache HugeGraph-Server before they are exploited. Our platform provides detailed reports, timely updates, and expert recommendations to enhance your cybersecurity posture. Protect your infrastructure with our advanced, easy-to-use solutions and stay ahead of potential threats.

References:

Solution Advice
  • Upgrade Apache HugeGraph-Server to version 1.3.0 or later.
  • Implement strict input validation and sanitization for data processed by the gremlin component.
  • Employ robust authentication and authorization mechanisms to restrict access to critical endpoints.
  • Regularly monitor and audit server activity for any signs of exploitation or unusual behavior.
  • Apply network-level controls to limit access to the server from untrusted sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.