LDAP Injection Vulnerability in Apache HertzBeat Affects User Security
CVE-2025-48208

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 September 2025

What is CVE-2025-48208?

An LDAP Injection vulnerability has been identified in Apache HertzBeat, where improper neutralization of special elements in an LDAP query can lead to arbitrary script execution. The vulnerability requires an authenticated user to exploit it by crafting custom commands. It affects users of HertzBeat up to version 1.7.2. To mitigate this risk, upgrading to version 1.7.3 is strongly recommended, ensuring enhanced security and protection against potential attacks.

Affected Version(s)

Apache HertzBeat (incubating) 0 <= 1.7.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F10wers13eiCHeng
aftersnow
.
CVE-2025-48208 : LDAP Injection Vulnerability in Apache HertzBeat Affects User Security