Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without authorization. Version 1.2.1 contains a patch for this issue.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Aug 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache hertzbeat |
|
CPEs | cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dromara
Dromara hertzbeat |
Apache
Apache hertzbeat |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-12-22T15:06:04.941Z
Updated: 2024-08-03T12:00:44.134Z
Reserved: 2022-09-02T14:16:35.876Z
Link: CVE-2022-39337
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-22T15:15:07.810
Modified: 2024-11-21T07:18:03.993
Link: CVE-2022-39337
Redhat
No data.