Apache HugeGraph users are being told to install a patch immediately to stay safe from this dangerous bug

Months after a patch was released, a vulnerability in the Apache HugeGraph server is being exploited to allow remote code execution (RCE) on vulnerable endpoints.

The nonprofit security organization Shadowserver Foundation sounded the alarm about Mastodon, noting: “We are observing Apache HugeGraph-Server CVE-2024-27348 RCE “POST /gremlin” exploitation attempts from multiple sources,” the alert read. “PoC code has been public since early June. If you are using HugeGraph, please ensure you update.”