Apache圖像資料庫HugeGraph重大層級漏洞出現攻擊行動
支付動態 · 2024-07-19

Shadowserver基金會警告,今年4月Apache基金會修補的圖像資料庫HugeGraph漏洞CVE-2024-27348出現攻擊行動,由於已有資安業者公布細節,很有可能有更多駭客藉此將其用於實際攻擊

今年4月Apache基金會針對圖像資料庫HugeGraph修補重大層級漏洞CVE-2024-27348,事隔3個月傳出有人將其用於攻擊行動的情況。

這項漏洞出現在gremlin元件,為命令執行弱點,影響1.0.0版以上的HugeGraph伺服器,而且是執行Java 8及Java 11版的應用程式環境。對此,Apache基金會提供1.3.0版HugeGraph予以修補,並呼籲用戶升級新版軟體之餘,還要採用Java 11的環境、啟用身分驗證系統,才能緩解漏洞,CVSS風險評分達到9.8。

事隔一個多月,滲透測試業者SecureLayer7揭露相關細節,並指出這項漏洞相當危險,攻擊者一旦利用,就能夠繞過沙箱的限制,達到執行程式碼的目的,進一步控制HugeGraph伺服器。

本週Shadowserver基金會提出警告,他們察覺有多個攻擊來源,發出POST /gremlin請求,試圖觸發CVE-2024-27348的情況,呼籲IT人員必須儘速採取行動,套用新版軟體。不過,該基金會並未透露攻擊來源的數量,也沒有公布曝露風險的HugeGraph伺服器臺數。

熱門文章
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Indiana online casino bill stalls in House committee
Regulation
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
Kazakhstan plans to penalise online casino promotions
Regulation
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
首頁
遊戲
合作
發現
我的