PT-2023-31868 · Hertzbeat · Hertzbeat
Pbuff07
·
Published
2023-12-22
·
Updated
2024-08-28
·
CVE-2023-51650
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hertzbeat versions prior to 1.4.1
Description
Hertzbeat is an open source, real-time monitoring system. Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces, potentially resulting in the disclosure of sensitive server information.
Recommendations
For versions prior to 1.4.1, update to version 1.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable interfaces until the update can be applied.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hertzbeat