Back to Database
Status published
Critical
CVE-2023-51389
HertzBeat SnakeYAML Deser RCE
Vulnerability Description
Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixes this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-51389
Credits & Attribution
No credits recorded in the NVD database.
References
More from dromara
View All →CVE-2023-51653
Hertzbeat JMX JNDI RCE
Critical
9.8
CVE-2023-51650
Unauthorized access vulnerability on three interfaces
High
7.5
CVE-2023-51388
HertzBeat AviatorScript Inject RCE
Critical
9.8
CVE-2023-51387
Expression Injection Vulnerability in Hertzbeat
High
7.2
CVE-2022-39337
Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat
High
7.5
Affected Vendor
dromara
View all reports →Affected Software
hertzbeat
Vulnerable Versions:
< 1.4.1
Timeline
Official Publish:
February 22nd, 2024
Last Modified:
August 22nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H