Loading HuntDB...

GHSA-29rc-vq7f-x335

GitHub Security Advisory

Apache HugeGraph-Server: Command execution in gremlin

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11

Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

Affected Packages

Maven org.apache.hugegraph:hugegraph-api
Affected versions: 1.0.0 (fixed in 1.3.0)
Maven org.apache.hugegraph:hugegraph-core
Affected versions: 1.0.0 (fixed in 1.3.0)

Related CVEs

Key Information

GHSA ID
GHSA-29rc-vq7f-x335
Published
April 22, 2024 3:30 PM
Last Modified
February 13, 2025 7:00 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.hugegraph:hugegraph-api
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 26, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.