漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache HugeGraph-Server: RAFT and deserialization vulnerability
Vulnerability Description
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache HugeGraph-Server 安全漏洞
Vulnerability Description
Apache HugeGraph-Server是Apache基金会的一个图数据库的服务端进程。 Apache HugeGraph-Server存在安全漏洞,该漏洞源于PD存储中不安全的Hessian反序列化,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A