Apache Software Foundation Apache Hertzbeat vulnerabilities
8 known vulnerabilities affecting apache_software_foundation/apache_hertzbeat.
Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-42323P2HIGHCVSS 8.8PoCfixed in 1.6.02024-09-21
CVE-2024-42323 [HIGH] CWE-502 CVE-2024-42323: SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulner
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).
This vulnerability can only be exploited by authorized attackers.
This issue affects Apache HertzBeat (incubating): before 1.6.0.
Users are recommended to upgrade to version 1.6.0, which fixes the issue.
nvd
CVE-2025-48208P2HIGHCVSS 8.8≤ 1.7.22025-09-09
CVE-2025-48208 [HIGH] CWE-90 CVE-2025-48208: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .
The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom commands. A successful attack would result in arbitrary script execution.
This issue affects Apache HertzBeat
nvd
CVE-2024-45505P3HIGHCVSS 8.8fixed in 1.6.12024-11-18
CVE-2024-45505 [HIGH] CWE-77 CVE-2024-45505: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating).
This vulnerability can only be exploited by authorized attackers.
This issue affects Apache HertzBeat (incubating): before 1.6.1.
Users are recommended to upgrade to version 1.6.1, which fixes the issue.
nvd
CVE-2026-24343P3HIGHCVSS 8.8≥ 1.7.1, < 1.8.02026-02-10
CVE-2026-24343 [HIGH] CWE-643 CVE-2026-24343: Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache
Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
nvd
CVE-2024-41151P3HIGHCVSS 8.8fixed in 1.6.12024-11-18
CVE-2024-41151 [HIGH] CWE-502 CVE-2024-41151: Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be
Deserialization of Untrusted Data vulnerability in Apache HertzBeat.
This vulnerability can only be exploited by authorized attackers.
This issue affects Apache HertzBeat: before 1.6.1.
Users are recommended to upgrade to version 1.6.1, which fixes the issue.
nvd
CVE-2025-24404P3HIGHCVSS 8.8fixed in 1.7.02025-09-09
CVE-2025-24404 [HIGH] CWE-91 CVE-2025-24404: XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.
The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability.
This issue affects Apache HertzBeat (incubating): before 1.7.0.
Users are recommended to upgrade to version 1.7
nvd
CVE-2024-45791P3HIGHCVSS 7.5fixed in 1.6.12024-11-18
CVE-2024-45791 [HIGH] CWE-200 CVE-2024-45791: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: before 1.6.1.
Users are recommended to upgrade to version 1.6.1, which fixes the issue.
nvd
CVE-2024-56736P3MEDIUMCVSS 6.5fixed in 1.7.02025-04-16
CVE-2024-56736 [MEDIUM] CWE-918 CVE-2024-56736: Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache Her
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat (incubating): before 1.7.0.
Users are recommended to upgrade to version 1.7.0, which fixes the issue.
nvd