RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
https://research.checkpoint.com/2024/22nd-july-threat-intelligence-report/
https://thehackernews.com/2024/07/critical-apache-hugegraph-vulnerability.html
https://www.theregister.com/2024/06/07/poc_apache_hugegraph/
https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9
https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9
https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication
https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication