CVE-2024-45505: Apache Hertzbeat

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.

Affected products

  • Apache Hertzbeat: before 1.6.1 (fixed in 1.6.1)

Published 2024-11-18. Last modified 2026-06-17.