Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0.
Users are recommended to upgrade to version 1.3.0, which fixes the issue.
{ "vanir_signatures": [ { "digest": { "function_hash": "289532015406295083540638038573374883908", "length": 115.0 }, "signature_type": "Function", "source": "https://github.com/apache/incubator-hugegraph/commit/6a4041e21c437b6e22d8a78e81f825bc0ab48a3d", "signature_version": "v1", "target": { "file": "hugegraph-server/hugegraph-core/src/main/java/org/apache/hugegraph/version/CoreVersion.java", "function": "check" }, "deprecated": false, "id": "CVE-2024-27349-24b8f36f" }, { "digest": { "threshold": 0.9, "line_hashes": [ "302589379334584903210079925347138763757", "157274152894967818629620008148175085715", "232801669051996050278526430629148727791", "333617038057953660713699047207001805296", "289690575160590398087158737328250586146", "64197837361715246154000480095721678854", "149380582586459330258374683320439375413" ] }, "signature_type": "Line", "source": "https://github.com/apache/incubator-hugegraph/commit/6a4041e21c437b6e22d8a78e81f825bc0ab48a3d", "signature_version": "v1", "target": { "file": "hugegraph-server/hugegraph-core/src/main/java/org/apache/hugegraph/version/CoreVersion.java" }, "deprecated": false, "id": "CVE-2024-27349-c79e6dcb" } ] }