CVE-2024-42323

Source
https://cve.org/CVERecord?id=CVE-2024-42323
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42323.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-42323
Published
2024-09-21T09:30:15.295Z
Modified
2026-07-15T01:48:59.230337443Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache HertzBeat: RCE by snakeYaml deser load malicious xml
Details

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). 

This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0.

Users are recommended to upgrade to version 1.6.0, which fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/42xxx/CVE-2024-42323.json",
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "1.6.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "1.6.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-502"
    ]
}
References

Affected packages

Git / github.com/apache/hertzbeat

Affected ranges

Type
GIT
Repo
https://github.com/apache/hertzbeat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.6.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-42323.json"