Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat
CVE-2022-39337
7.5HIGH
What is CVE-2022-39337?
Hertzbeat, an open source real-time monitoring system, is vulnerable to a permission bypass which allows unauthorized users to bypass authentication mechanisms. This vulnerability enables attackers to invoke system interfaces without proper authorization, potentially leading to unauthorized access and manipulation of sensitive resources. The issue affects all Hertzbeat versions up to 1.20. To mitigate this vulnerability, users are advised to upgrade to version 1.2.1 where a patch has been implemented to secure the system.
Affected Version(s)
hertzbeat <= 1.2.0
