CVE-2024-42323
Apache HertzBeat: RCE by snakeYaml deser load malicious xml
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 4.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
21 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).
This vulnerability can only be exploited by authorized attackers.
This issue affects Apache HertzBeat (incubating): before 1.6.0.
Users are recommended to upgrade to version 1.6.0, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache HertzBeatWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →