Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q37j-3367-fwv7

Опубликовано: 12 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.1

Описание

Apache HugeGraph-Server: RAFT and deserialization vulnerability

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks.

Users are recommended to upgrade to version 1.7.0, which fixes the issue.

Пакеты

Наименование

org.apache.hugegraph:hg-pd-core

maven
Затронутые версииВерсия исправления

< 1.7.0

1.7.0

EPSS

Процентиль: 81%
0.01479
Низкий

8.1 High

CVSS4

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

EPSS

Процентиль: 81%
0.01479
Низкий

8.1 High

CVSS4

Дефекты

CWE-502