CVE-2024-42362
published 2024-08-20CVE-2024-42362: Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.33%
67.9th percentile
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hertzbeat | < 1.6.0 | 1.6.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/apache/hertzbeat/commit/79f5408e345e8e89da97be05f43e3204a950ddfbhttps://github.com/apache/hertzbeat/commit/9dbbfb7812fc4440ba72bdee66799edd519d06bbhttps://github.com/apache/hertzbeat/pull/1611https://github.com/apache/hertzbeat/pull/1620https://github.com/apache/hertzbeat/pull/1620/files#diff-9c5fb3d1b7e3b0f54bc5c4182965c4fe1f9023d449017cece3005d3f90e8e4d8https://securitylab.github.com/advisories/GHSL-2023-254_GHSL-2023-256_HertzBeat/
2024-08-20
Published