Apache HertzBeat Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in Apache HertzBeat (incubating) versions prior to 1.7.0. This vulnerability allows an attacker to make unauthorized requests from the server, potentially leading to exposure of internal resources or services.

Impact

Exploitation of this vulnerability could allow an attacker to manipulate server-side requests, potentially accessing internal services or resources that are not exposed to the public.

Remediation

Users are advised to upgrade to Apache HertzBeat version 1.7.0 or later, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.