Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tomsun28

#29649of 53,630
8.8Total CVSS
Vulnerabilities · 1
PT-2024-29897
8.8
2024-08-20
Hertzbeat · Hertzbeat · CVE-2024-42362
**Name of the Vulnerable Software and Affected Versions** Hertzbeat versions prior to 1.6.0 **Description** Hertzbeat is an open source, real-time monitoring system. It has an authenticated Remote Code Execution (RCE) vulnerability via unsafe deserialization in the "/api/monitors/import" API endpoint. **Recommendations** For versions prior to 1.6.0, update to version 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/monitors/import" API endpoint until the update is applied.