CVE-2024-27347 Overview
CVE-2024-27347 is a Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble, the web-based visualization and management interface for the Apache HugeGraph database. The flaw affects versions 1.0.0 through versions prior to 1.3.0. An unauthenticated remote attacker can abuse the application to issue HTTP requests to arbitrary destinations reachable from the Hubble server. This can expose internal services, cloud metadata endpoints, or other resources that should not be accessible from external networks. The Apache HugeGraph project classifies the issue under CWE-918: Server-Side Request Forgery. Upgrading to version 1.3.0 resolves the vulnerability.
Critical Impact
Unauthenticated attackers can coerce the Hubble server into issuing arbitrary outbound HTTP requests, enabling reconnaissance of internal networks and disclosure of confidential information.
Affected Products
- Apache HugeGraph-Hubble 1.0.0
- Apache HugeGraph-Hubble versions after 1.0.0 and before 1.3.0
- Deployments exposing Hubble to untrusted networks
Discovery Timeline
- 2024-04-22 - CVE CVE-2024-27347 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-27347
Vulnerability Analysis
Apache HugeGraph-Hubble provides a management console for HugeGraph, including features that initiate HTTP connections to backend graph servers. The vulnerable code paths accept a user-controlled URL or host parameter and dispatch a server-side HTTP request without validating the destination. Attackers can substitute internal targets, including loopback addresses, RFC1918 ranges, and cloud instance metadata services such as 169.254.169.254.
Because the request originates from the Hubble server, it bypasses perimeter firewalls and reaches hosts that external clients cannot address directly. Responses or response metadata may be reflected to the attacker, leaking data from internal applications. Review the Apache mailing list announcement and the OSS Security discussion for the official disclosure details.
Root Cause
The root cause is missing or insufficient validation of outbound request destinations [CWE-918]. HugeGraph-Hubble treats connection parameters supplied by API clients as trusted and does not enforce an allowlist of permissible hosts, schemes, or ports before invoking its HTTP client.
Attack Vector
Exploitation requires only network access to the Hubble web interface. No authentication or user interaction is needed. An attacker submits a crafted request to an affected API endpoint with the URL parameter pointing at an internal resource. The Hubble process then performs the HTTP request on the attacker's behalf and may return response data, status codes, or timing information that leaks internal network topology.
No verified public proof-of-concept code is available at this time. Refer to the vendor advisory for technical specifics.
Detection Methods for CVE-2024-27347
Indicators of Compromise
- Outbound HTTP connections from HugeGraph-Hubble hosts to loopback addresses, link-local ranges, or internal subnets not associated with legitimate graph backends.
- Hubble access logs containing API requests with URL parameters pointing to 127.0.0.1, 169.254.169.254, or RFC1918 addresses.
- Unexpected DNS resolutions for internal hostnames originating from the Hubble service account.
Detection Strategies
- Inspect Hubble HTTP access logs for parameters containing full URLs or host values that deviate from expected backend graph server addresses.
- Correlate network flow records to identify Hubble processes communicating with cloud metadata endpoints or management interfaces.
- Deploy web application firewall rules that reject requests to Hubble endpoints when parameters embed URLs targeting private address space.
Monitoring Recommendations
- Enable verbose request logging on Hubble and forward events to a centralized SIEM for retention and correlation.
- Alert on any egress traffic from the Hubble host to 169.254.169.254 or other cloud metadata services.
- Baseline normal Hubble outbound destinations and alert on deviations from the established pattern.
How to Mitigate CVE-2024-27347
Immediate Actions Required
- Upgrade Apache HugeGraph-Hubble to version 1.3.0 or later as recommended by the project maintainers.
- Restrict network access to the Hubble management interface so only trusted administrators can reach it.
- Place Hubble behind an authenticating reverse proxy if it must remain network-accessible.
Patch Information
The Apache HugeGraph project released version 1.3.0 to address CVE-2024-27347. Operators running any release in the 1.0.0 through pre-1.3.0 range should upgrade immediately. See the Apache HugeGraph security announcement for official guidance and release artifacts.
Workarounds
- Enforce egress filtering on the Hubble host to block outbound traffic to loopback, link-local, and internal subnets that Hubble does not legitimately require.
- Block access to cloud instance metadata services from the Hubble network segment, or require IMDSv2 session tokens on AWS deployments.
- Isolate Hubble on a dedicated network segment with strict allowlists for approved HugeGraph backend servers.
# Example egress restriction using iptables to block metadata service access
iptables -A OUTPUT -m owner --uid-owner hugegraph -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner hugegraph -d 127.0.0.0/8 ! -o lo -j REJECT
iptables -A OUTPUT -m owner --uid-owner hugegraph -d 10.0.0.0/8 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.