Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 16 Jan 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache hertzbeat |
|
| CPEs | cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache hertzbeat |
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-02-22T15:53:46.458Z
Updated: 2024-08-14T19:09:04.986Z
Reserved: 2023-12-18T19:35:29.003Z
Link: CVE-2023-51388
Updated: 2024-08-02T22:32:09.231Z
Status : Analyzed
Published: 2024-02-22T16:15:53.413
Modified: 2025-01-16T19:11:41.830
Link: CVE-2023-51388
No data.