CVE-2024-45505

CWE-77Command Injection3 documents3 sources
Severity
8.8HIGH
EPSS
4.2%
top 11.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8c78-wf5j-v7jx: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating)2024-11-18
CVEList
Apache HertzBeat: Exists Native Deser RCE and file writing vulnerabilities2024-11-18
CVE-2024-45505 (HIGH CVSS 8.8) | Improper Neutralization of Special | cvebase.io