Описание
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.
Ссылки
- Release Notes
- ExploitVendor Advisory
- Release Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.1 (исключая)
cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00466
Низкий
7.5 High
CVSS3
Дефекты
CWE-862
EPSS
Процентиль: 64%
0.00466
Низкий
7.5 High
CVSS3
Дефекты
CWE-862