# Apache HugeGraph-Server: 修复 JWT Token(Secret)漏洞
## 概述
Apache HugeGraph-Server 存在一个基于假设不可变数据的身份验证绕过漏洞。
## 影响版本
- 影响版本:1.0.0 到 1.5.0(不包括 1.5.0)
## 细节
该漏洞允许攻击者通过利用假设不可变的数据绕过身份验证机制。
## 影响
用户建议升级到 1.5.0 版本以修复此问题。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E6%95%B0%E6%8D%AE%E5%BA%93%E6%BC%8F%E6%B4%9E/Apache%20HugeGraph%20JWT%20Token%20%E5%AF%86%E9%92%A5%E7%A1%AC%E7%BC%96%E7%A0%81%E6%BC%8F%E6%B4%9E%20CVE-2024-43441.md | POC详情 |
| 2 | https://github.com/vulhub/vulhub/blob/master/hugegraph/CVE-2024-43441/README.md | POC详情 | |
| 3 | Apache HugeGraph-Server versions prior to 1.5.0 contain an authentication bypass vulnerability caused by assumed-immutable data. This flaw allows attackers to bypass authentication mechanisms without requiring specific privileges or user interaction. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43441.yaml | POC详情 |
标题: CVE-2024-43441: Apache HugeGraph-Server: Fixed JWT Token(Secret)-Apache Mail Archives -- 🔗来源链接
标签: vendor-advisory
暂无评论