CVE-2025-24404 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with acc…
High CVSS: 8.8

CVE-2025-24404

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.












The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability.

This issue affects Apache HertzBeat (incubating): before 1.7.0.

Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Vendor
Apache
Product
Hertzbeat
CWE
CWE-91
Yayın Tarihi
2025-09-09 10:15:33
Güncelleme
2025-11-04 22:16:07
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar