PoC Index

CVE-2024-42323

HIGH 8.8EPSS 8.3%

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers.This issue affects Apache HertzBeat (incubating): before 1.6.0.Users are recommended to upgrade to version 1.6.0, which fixes the issue.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
8.32% chance of exploitation in the next 30 days, 95th percentile
Nuclei
high · CWE-502
Published
2024-09-21
Updated
2024-09-23

Proof-of-concept exploits (1)

Nuclei templates (1)

Vulhub environments (1)

References

Related