====================================================================== CERT-Renater Note d'Information No. 2024/VULN478 _____________________________________________________________________ DATE : 19/11/2024 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Apache HertzBeat versions prior to 1.6.1. ===================================================================== https://lists.apache.org/thread/p33tg0vo5nh6kscth4262ktsqo3h5lqo https://lists.apache.org/thread/jmbsfjsvrfnvosh1ftrm3ry4j3sb7doz https://lists.apache.org/thread/gvbc68krhqhht7mkkkx7k13k6k6fdhy0 _____________________________________________________________________ CVE-2024-41151: Apache HertzBeat: RCE by notice template injection vulnerability Severity: moderate Affected versions: - Apache HertzBeat before 1.6.1 Description: Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. Credit: Li Yi Wei (finder) Elin Kai (finder) References: https://www.cve.org/CVERecord?id=CVE-2024-41151 _____________________________________________________________________ CVE-2024-45791: Apache HertzBeat: Exposure sensitive token via http GET method with query string Severity: low Affected versions: - Apache HertzBeat before 1.6.1 Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. Credit: Ícaro Torres (finder) References: https://www.cve.org/CVERecord?id=CVE-2024-45791 _____________________________________________________________________ CVE-2024-45505: Apache HertzBeat (incubating): Exists Native Deser RCE and file writing vulnerabilities Severity: moderate Affected versions: - Apache HertzBeat (incubating) before 1.6.1 Description: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. Credit: Unam4 (finder) Springkilll (finder) yemoli (finder) yulate (finder) References: https://www.cve.org/CVERecord?id=CVE-2024-45505 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================