LDAP Injection Vulnerability in Apache HertzBeat Affects User Security
CVE-2025-48208
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-48208?
An LDAP Injection vulnerability has been identified in Apache HertzBeat, where improper neutralization of special elements in an LDAP query can lead to arbitrary script execution. The vulnerability requires an authenticated user to exploit it by crafting custom commands. It affects users of HertzBeat up to version 1.7.2. To mitigate this risk, upgrading to version 1.7.3 is strongly recommended, ensuring enhanced security and protection against potential attacks.
Affected Version(s)
Apache HertzBeat (incubating) 0 <= 1.7.2