Apache HertzBeat LDAP Injection Vulnerability Allowing Arbitrary Script Execution

Vulnerability

A vulnerability allowing LDAP injection has been identified in Apache HertzBeat versions through 1.7.2. This issue arises from improper neutralization of special elements in LDAP queries, enabling authenticated attackers with access to execute arbitrary scripts by crafting custom commands.

Impact

Exploitation of this vulnerability could lead to unauthorized script execution on the server.

Remediation

Users are advised to upgrade to Apache HertzBeat version 1.7.3 or later, which addresses this vulnerability.

Added: Sep 9, 2025, 10:17 AM
Updated: Sep 9, 2025, 4:55 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.