PT-2023-13720 · Hertzbeat · Hertzbeat

2Xiaodi

·

Published

2023-12-22

·

Updated

2024-08-28

·

CVE-2022-39337

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hertzbeat versions 1.20 and prior
Description Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless capabilities. The system has a permission bypass issue, allowing system authentication to be bypassed and interfaces to be invoked without authorization.
Recommendations For Hertzbeat versions 1.20 and prior, update to version 1.2.1 or later, which contains a patch for this issue. As a temporary workaround, consider restricting access to sensitive interfaces until the patch can be applied.

Exploit

Fix

Incorrect Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-39337
GHSA-434F-F5CW-3RJ6

Affected Products

Hertzbeat