Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-02-22T15:53:46.458Z
Updated: 2024-08-14T19:09:04.986Z
Reserved: 2023-12-18T19:35:29.003Z
Link: CVE-2023-51388
Vulnrichment
Updated: 2024-08-02T22:32:09.231Z
NVD
Status : Awaiting Analysis
Published: 2024-02-22T16:15:53.413
Modified: 2024-02-22T19:07:27.197
Link: CVE-2023-51388
Redhat
No data.