XML Injection Vulnerability in Apache HertzBeat
CVE-2025-24404
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-24404?
An XML Injection vulnerability has been identified in Apache HertzBeat, specifically affecting versions prior to 1.7.0. This vulnerability allows an authorized attacker to exploit XML parsing processes within the application by injecting malicious content into the HTTP sitemap XML response. By successfully manipulating how the application processes XML, an attacker can potentially execute remote commands, leading to unauthorized access and control over the system. It is crucial for users to upgrade to version 1.7.0 to mitigate this risk and protect their environments.
Affected Version(s)
Apache HertzBeat (incubating) 0 < 1.7.0