PT-2023-13720 · Hertzbeat · Hertzbeat
2Xiaodi
·
Published
2023-12-22
·
Updated
2024-08-28
·
CVE-2022-39337
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hertzbeat versions 1.20 and prior
Description
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless capabilities. The system has a permission bypass issue, allowing system authentication to be bypassed and interfaces to be invoked without authorization.
Recommendations
For Hertzbeat versions 1.20 and prior, update to version 1.2.1 or later, which contains a patch for this issue. As a temporary workaround, consider restricting access to sensitive interfaces until the patch can be applied.
Exploit
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hertzbeat