Unauthorized Access Vulnerabilities in Hertzbeat Monitoring System

Unauthorized Access Vulnerabilities in Hertzbeat Monitoring System

CVE-2023-51650 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.

Learn more about our Cis Benchmark Audit For Server Software.