PT-2023-31868 · Hertzbeat · Hertzbeat

Pbuff07

·

Published

2023-12-22

·

Updated

2024-08-28

·

CVE-2023-51650

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hertzbeat versions prior to 1.4.1
Description Hertzbeat is an open source, real-time monitoring system. Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces, potentially resulting in the disclosure of sensitive server information.
Recommendations For versions prior to 1.4.1, update to version 1.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable interfaces until the update can be applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-51650
GHSA-RRC5-QPXR-5JM2

Affected Products

Hertzbeat