CVE-2024-43441 is a critical Authentication Bypass vulnerability affecting Apache HugeGraph-Server versions from 1.0.0 before 1.5.0. This flaw allows unauthenticated attackers to bypass security mechanisms due to assumed-immutable data. With a CVSS score of 9.8 (Critical), it presents a severe risk, enabling full compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction. While not yet listed in CISA's KEV catalog, Nuclei templates exist for exploitation, and it has garnered significant community discussion and media coverage, including warnings from the Cyber Security Agency of Singapore.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.5.0CPE matchmatch criteria | cpe:2.3:a:apache:hugegraph:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.