Описание
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without authorization. Version 1.2.1 contains a patch for this issue.
Ссылки
- Patch
- ExploitIssue Tracking
- Issue TrackingPatch
- Vendor Advisory
- Patch
- ExploitIssue Tracking
- Issue TrackingPatch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.1 (исключая)
cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00225
Низкий
7.5 High
CVSS3
Дефекты
CWE-284
EPSS
Процентиль: 45%
0.00225
Низкий
7.5 High
CVSS3
Дефекты
CWE-284