oss-sec mailing list archives
CVE-2024-42323: Apache HertzBeat: RCE by snakeYaml deser load malicious xml
From: Chao Gong <gongchao () apache org>
Date: Sat, 21 Sep 2024 02:27:45 +0000
Severity: important Affected versions: - Apache HertzBeat before 1.6.0 Description: SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue. Credit: Yulate (reporter) Liufeng Yi (reporter) References: https://www.cve.org/CVERecord?id=CVE-2024-42323
Current thread:
- CVE-2024-42323: Apache HertzBeat: RCE by snakeYaml deser load malicious xml Chao Gong (Sep 21)
