CVE-2022-39337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/12/2023
Last modified:
28/08/2024

Description

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without authorization. Version 1.2.1 contains a patch for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:* 1.2.1 (excluding)