logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-51388

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-51388

Description:
Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in AviatorScript (which can execute any static method by default) script injection. Version 1.4.1 fixes this vulnerability.
Last updated date:
01/16/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/16/2025
Reference url to background

https://github.com/dromara/hertzbeat/security/advisories/GHSA-mcqg-gqxr-hqgj

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy