CVE-2024-42362: Apache Hertzbeat
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.
Affected products
- Apache Hertzbeat: before 1.6.0 (fixed in 1.6.0)
Published 2024-08-20. Last modified 2026-06-17.