Skip to main content

Authentication Bypass by Assumed-Immutable Data

CVE-2024-43441

Severity High
Score 9.8/10

Summary

Authentication Bypass by Assumed-Immutable Data vulnerability in org.apache.hugegraph:hugegraph-core package versions 1.x prior to 1.5.0. Users are recommended to upgrade to a version which fixes the issue.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-302 - Authentication Bypass by Assumed-Immutable Data

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Advisory Timeline

  • Published