PT-2023-31868 · Hertzbeat · Hertzbeat

Pbuff07

·

Publicado

2023-12-22

·

Atualizado

2024-08-28

·

CVE-2023-51650

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hertzbeat versions prior to 1.4.1
Description Hertzbeat is an open source, real-time monitoring system. Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces, potentially resulting in the disclosure of sensitive server information.
Recommendations For versions prior to 1.4.1, update to version 1.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable interfaces until the update can be applied.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-51650
GHSA-RRC5-QPXR-5JM2

Produtos afetados

Hertzbeat