Hertzbeat Monitoring System Vulnerability Fix
CVE-2023-51388
9.8CRITICAL
What is CVE-2023-51388?
A security vulnerability in Hertzbeat, a real-time monitoring system, allows for script injection due to the use of AviatorEvaluator in the CalculateAlarm.java component. The absence of a security policy facilitates the execution of arbitrary static methods through AviatorScript, exposing the system to potential malicious exploits. This vulnerability affects version 1.4.1 of Hertzbeat, which has since addressed the issue with an updated release.
Affected Version(s)
hertzbeat < 1.4.1
