Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qj3-h82r-hcwc

Опубликовано: 21 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). 

This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0.

Users are recommended to upgrade to version 1.6.0, which fixes the issue.

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). 

This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0.

Users are recommended to upgrade to version 1.6.0, which fixes the issue.

EPSS

Процентиль: 99%
0.69984
Средний

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.

EPSS

Процентиль: 99%
0.69984
Средний

8.8 High

CVSS3

Дефекты

CWE-502