CVE-2025-24404

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/09/2025
Last modified:
04/11/2025

Description

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability.<br /> <br /> This issue affects Apache HertzBeat (incubating): before 1.7.0.<br /> <br /> Users are recommended to upgrade to version 1.7.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:* 1.7.0 (excluding)