First published: Sat Nov 16 2024(Updated: )
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dromara Hertzbeat | <1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45505 is considered to have a high severity due to its potential for command injection by authorized attackers.
To fix CVE-2024-45505, upgrade Apache HertzBeat to version 1.6.1 or later.
CVE-2024-45505 affects users of Apache HertzBeat versions prior to 1.6.1.
CVE-2024-45505 is an improper neutralization vulnerability that allows for command injection.
CVE-2024-45505 cannot be exploited remotely as it requires authorization for an attack.