Apache HugeGraph-Server Bug Actively Exploited, CISA Warns
The US Cybersecurity and Infrastructure Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a critical remote code execution flaw affecting Apache HugeGraph-Server. The CVE-2024-27348 vulnerability, rated 9.8, impacts versions from 1.0.0 to 1.3.0 and allows improper access control. Apache fixed the vulnerability in April 2024 by releasing version 1.3.0. … Read more