Target Industry
Indiscriminate, opportunistic targeting.
Overview
Apache HugeGraph is an open-source graph database system. A severe security flaw has been discovered that arose from missing reflection filtering within the HugeSecurityManager, allowing for the manipulation of task/threats names, which meant security measures were bypassed.
Tracked as CVE-2024-27348 (CVSS 3.1 base score: 9.8), the relevant security update should be applied as a matter of urgency where possible.
Impact
Successful exploitation of CVE-2024-27348 could allow attackers to bypass sandbox restrictions and conduct remote code execution (RCE).
Targeted Organisations
As of the time of writing, no specific organisations were targeted apart from Apache HugeGraph.
Affected Products
Apache HugeGraph-Server 1.0.0 versions prior to 1.3.0 in Java8 and Java11.
Containment, Mitigations & Remediations
It is strongly recommended that upgrading to version 1.3.0 with Java11 and enabling of the authentication system are carried out as soon as possible.
Indicators of Compromise
No specific Indicators of Compromise (IoCs) are available currently.
Threat Landscape
Apache HugeGraph occupies a significant portion of graph database utilisation. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to focus on, Fluent Bit is a prime target. Due to the fact that Apache HugeGraph has become an integral aspect of business operations, threat actors will continue to exploit vulnerabilities contained within the associated products in an attempt to extract the sensitive data contained therein.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.













