Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0.
Users are recommended to upgrade to version 1.3.0, which fixes the issue.
[
{
"digest": {
"function_hash": "289532015406295083540638038573374883908",
"length": 115.0
},
"id": "CVE-2024-27349-24b8f36f",
"signature_type": "Function",
"source": "https://github.com/apache/incubator-hugegraph/commit/6a4041e21c437b6e22d8a78e81f825bc0ab48a3d",
"signature_version": "v1",
"target": {
"file": "hugegraph-server/hugegraph-core/src/main/java/org/apache/hugegraph/version/CoreVersion.java",
"function": "check"
},
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"302589379334584903210079925347138763757",
"157274152894967818629620008148175085715",
"232801669051996050278526430629148727791",
"333617038057953660713699047207001805296",
"289690575160590398087158737328250586146",
"64197837361715246154000480095721678854",
"149380582586459330258374683320439375413"
]
},
"id": "CVE-2024-27349-c79e6dcb",
"signature_type": "Line",
"source": "https://github.com/apache/incubator-hugegraph/commit/6a4041e21c437b6e22d8a78e81f825bc0ab48a3d",
"signature_version": "v1",
"target": {
"file": "hugegraph-server/hugegraph-core/src/main/java/org/apache/hugegraph/version/CoreVersion.java"
},
"deprecated": false
}
]