Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Apache HugeGraph Vulnerability Exploited in Wild

A recently patched Apache HugeGraph-Server vulnerability tracked as CVE-2024-27348 is being targeted in attacks.

Threat actors appear to be attempting to exploit a recently patched Apache HugeGraph vulnerability.

Apache HugeGraph is an open source graph database system that helps users easily build applications based on graph databases.

Its developers informed users in April about an important-severity flaw in HugeGraph-Server that can be exploited for remote command execution. The vulnerability, tracked as CVE-2024-27348, has been patched with the release of version 1.3.0.

The non-profit cybersecurity organization The Shadowserver Foundation reported on Tuesday that it has seen exploitation attempts targeting CVE-2024-27348. Shadowserver has seen attacks originating from eight IP addresses. 

The organization noted that attacks appear to have started on June 6, but increased last week. Proof-of-concept (PoC) exploit code for CVE-2024-27348 became available in early June. 

SecureLayer7 published technical details for the Apache HugeGraph vulnerability on June 5.

Advertisement. Scroll to continue reading.

The company assigned the flaw a ‘critical’ severity rating and warned that an attacker can exploit it to bypass sandbox restrictions and achieve remote code execution, enabling them to take complete control of the targeted server. 

Related: Organizations Warned of Exploited GeoServer Vulnerability

Related: APT Exploits Windows Zero-Day to Execute Code via Disabled Internet Explorer

Related: Exploitation Attempts Target New MOVEit Transfer Vulnerability

Related: Recent SolarWinds Serv-U Vulnerability Exploited in the Wild

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Chris Sistrunk has been promoted to Practice Leader for Mandiant's OT Security Consulting.

Nudge Security has appointed Patrick Dillon as its Chief Revenue Officer.

AutoNation has appointed Brian Fricke as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.