apache Vulnerabilities and Affected Products
Vulnerabilities associated with hertzbeat.
Products
Clear product- HTTP Server21 vulnerabilities
- OFBiz21 vulnerabilities
- Struts18 vulnerabilities
- inlong17 vulnerabilities
- Tomcat16 vulnerabilities
- airflow15 vulnerabilities
- Solr10 vulnerabilities
- traffic_server8 vulnerabilities
- ActiveMQ7 vulnerabilities
- linkis7 vulnerabilities
- cloudstack6 vulnerabilities
- cxf6 vulnerabilities
- dolphinscheduler6 vulnerabilities
- hertzbeat6 vulnerabilities
- http_server6 vulnerabilities
- pulsar6 vulnerabilities
- streampark6 vulnerabilities
- zeppelin6 vulnerabilities
- Apache HTTP Server5 vulnerabilities
- Apache Tomcat5 vulnerabilities
- kafka5 vulnerabilities
- ambari4 vulnerabilities
- Apache OFBiz4 vulnerabilities
- Apache Tika4 vulnerabilities
- camel4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-41151HIGH | Apache HertzBeat: RCE by notice template injection vulnerabilityDeserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. CWE-502Nov 18, 2024 | CVSS8.8v3.1 | EPSS0.955% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45791HIGH | Apache HertzBeat: Exposure sensitive token via http GET method with query stringExposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. CWE-200Nov 18, 2024 | CVSS7.5v3.1 | EPSS0.791% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45505HIGH | Apache HertzBeat: Exists Native Deser RCE and file writing vulnerabilitiesImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. CWE-77Nov 18, 2024 | CVSS8.8v3.1 | EPSS2.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42323HIGH | Apache HertzBeat: RCE by snakeYaml deser load malicious xmlSnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue. | CVSS8.8v3.1 | EPSS8.32% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-42362HIGH | GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/importHertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0. CWE-502Aug 20, 2024 | CVSS8.8v3.1 | EPSS1.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42361HIGH | GHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection. CWE-89Aug 20, 2024 | CVSS7.5v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |