Skip to content

Apache HugeGraph-Server: Fixed JWT Token (Secret)

Moderate severity GitHub Reviewed Published Dec 24, 2024 to the GitHub Advisory Database • Updated Dec 26, 2024

Package

maven org.apache.hugegraph:hugegraph-server (Maven)

Affected versions

>= 1.0.0, < 1.5.0

Patched versions

1.5.0

Description

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.

This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0.

Users are recommended to upgrade to version 1.5.0, which fixes the issue.

References

Published by the National Vulnerability Database Dec 24, 2024
Published to the GitHub Advisory Database Dec 24, 2024
Reviewed Dec 26, 2024
Last updated Dec 26, 2024

Severity

Moderate

EPSS score

0.043%
(11th percentile)

Weaknesses

CVE ID

CVE-2024-43441

GHSA ID

GHSA-f697-gm3h-xrf9
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.