PT-2024-29897 · Hertzbeat · Hertzbeat

Tomsun28

·

Published

2024-08-20

·

Updated

2024-08-28

·

CVE-2024-42362

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hertzbeat versions prior to 1.6.0
Description Hertzbeat is an open source, real-time monitoring system. It has an authenticated Remote Code Execution (RCE) vulnerability via unsafe deserialization in the "/api/monitors/import" API endpoint.
Recommendations For versions prior to 1.6.0, update to version 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/monitors/import" API endpoint until the update is applied.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-42362

Affected Products

Hertzbeat