CVE-2024-45505

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:23

Type Values Removed Values Added
References () https://lists.apache.org/thread/gvbc68krhqhht7mkkkx7k13k6k6fdhy0 - () https://lists.apache.org/thread/gvbc68krhqhht7mkkkx7k13k6k6fdhy0 - Mailing List, Vendor Advisory
References () https://lists.apache.org/thread/h8k14o1bfyod66p113pkgnt1s52p6p19 - () https://lists.apache.org/thread/h8k14o1bfyod66p113pkgnt1s52p6p19 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2024/11/16/4 - () http://www.openwall.com/lists/oss-security/2024/11/16/4 - Mailing List, Third Party Advisory
First Time Apache
Apache hertzbeat
CPE cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*

21 Nov 2024, 09:37

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/11/16/4 -

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando ('Inyección de comandos') en Apache HertzBeat (en incubación). Esta vulnerabilidad solo puede ser explotada por atacantes autorizados. Este problema afecta a Apache HertzBeat (en incubación): versiones anteriores a la 1.6.1. Se recomienda a los usuarios que actualicen a la versión 1.6.1, que soluciona el problema.

18 Nov 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

18 Nov 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 09:15

Updated : 2025-06-24 16:23


NVD link : CVE-2024-45505

Mitre link : CVE-2024-45505

CVE.ORG link : CVE-2024-45505


JSON object : View

Products Affected

apache

  • hertzbeat
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')