← back
CVE-2024-42323

Apache HertzBeat: RCE by snakeYaml deser load malicious xml

CVSS 8.8 HIGHEPSS 4.1%CWE-502
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 4.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →