Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.
References
| Link | Resource |
|---|---|
| https://github.com/dromara/hertzbeat/security/advisories/GHSA-rrc5-qpxr-5jm2 | Exploit Vendor Advisory |
| https://github.com/dromara/hertzbeat/releases/tag/v1.4.1 | Release Notes |
Configurations
Information
Published : 2023-12-22 21:15
Updated : 2024-01-03 19:53
NVD link : CVE-2023-51650
Mitre link : CVE-2023-51650
JSON object : View
Products Affected
dromara
- hertzbeat
CWE
CWE-862
Missing Authorization
