Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache hertzbeat |
|
CPEs | cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache hertzbeat |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-14T19:09:04.986Z
Reserved: 2023-12-18T19:35:29.003Z
Link: CVE-2023-51388

Updated: 2024-08-02T22:32:09.231Z

Status : Analyzed
Published: 2024-02-22T16:15:53.413
Modified: 2025-01-16T19:11:41.830
Link: CVE-2023-51388

No data.