← back
CVE-2023-51650

Unauthorized access vulnerability on three interfaces

CVSS 7.5 HIGHEPSS 0.9%CWE-862
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
dromara · hertzbeat

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →