Vulnerabilities > CVE-2024-42362 - Deserialization of Untrusted Data vulnerability in Apache Hertzbeat
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://securitylab.github.com/advisories/GHSL-2023-254_GHSL-2023-256_HertzBeat/
- https://github.com/apache/hertzbeat/pull/1611
- https://github.com/apache/hertzbeat/pull/1620
- https://github.com/apache/hertzbeat/pull/1620/files#diff-9c5fb3d1b7e3b0f54bc5c4182965c4fe1f9023d449017cece3005d3f90e8e4d8
- https://github.com/apache/hertzbeat/commit/79f5408e345e8e89da97be05f43e3204a950ddfb
- https://github.com/apache/hertzbeat/commit/9dbbfb7812fc4440ba72bdee66799edd519d06bb