Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-22 16:15
Updated : 2024-02-22 19:07
NVD link : CVE-2023-51388
Mitre link : CVE-2023-51388
CVE.ORG link : CVE-2023-51388
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')