CVE-2024-41151

Severity
8.8HIGH
EPSS
0.8%
top 26.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-jc5h-x77p-hhq6: Deserialization of Untrusted Data vulnerability in Apache HertzBeat2024-11-18
CVEList
Apache HertzBeat: RCE by notice template injection vulnerability2024-11-18
CVE-2024-41151 (HIGH CVSS 8.8) | Deserialization of Untrusted Data v | cvebase.io