Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.
References
Link | Resource |
---|---|
https://github.com/dromara/hertzbeat/releases/tag/v1.4.1 | Release Notes |
https://github.com/dromara/hertzbeat/security/advisories/GHSA-rrc5-qpxr-5jm2 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-12-22 21:15
Updated : 2024-01-03 19:53
NVD link : CVE-2023-51650
Mitre link : CVE-2023-51650
CVE.ORG link : CVE-2023-51650
JSON object : View
Products Affected
dromara
- hertzbeat
CWE
CWE-862
Missing Authorization