XML Injection Vulnerability in Apache HertzBeat
CVE-2025-24404

8.8HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 September 2025

What is CVE-2025-24404?

An XML Injection vulnerability has been identified in Apache HertzBeat, specifically affecting versions prior to 1.7.0. This vulnerability allows an authorized attacker to exploit XML parsing processes within the application by injecting malicious content into the HTTP sitemap XML response. By successfully manipulating how the application processes XML, an attacker can potentially execute remote commands, leading to unauthorized access and control over the system. It is crucial for users to upgrade to version 1.7.0 to mitigate this risk and protect their environments.

Affected Version(s)

Apache HertzBeat (incubating) 0 < 1.7.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

unam4
springkill
Zoiltin
.
CVE-2025-24404 : XML Injection Vulnerability in Apache HertzBeat