CVE-2023-51650: Apache Hertzbeat

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.

Affected products

  • Apache Hertzbeat: before 1.4.1 (fixed in 1.4.1)

Published 2023-12-22. Last modified 2026-06-17.