Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/import
Vulnerability Description
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Hertzbeat 安全漏洞
Vulnerability Description
Hertzbeat是dromara组织的一个开源的实时监控系统。 Hertzbeat 1.6.0 版本之前存在安全漏洞,该漏洞源于 /api/monitors/import 位置存在一个不安全的反序列化问题,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A