CVE-2023-51388

CWE-742 documents2 sources
Severity
9.8CRITICAL
EPSS
0.8%
top 25.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/hertzbeat< 1.4.1
CVEListV5dromara/hertzbeat< 1.4.1

Patches

🔴Vulnerability Details

1
CVEList
HertzBeat AviatorScript Inject RCE2024-02-22
CVE-2023-51388 (CRITICAL CVSS 9.8) | Hertzbeat is a real-time monitoring | cvebase.io