Apache HertzBeat
cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*
- <= 1.7.2
A vulnerability allowing LDAP injection has been identified in Apache HertzBeat versions through 1.7.2. This issue arises from improper neutralization of special elements in LDAP queries, enabling authenticated attackers with access to execute arbitrary scripts by crafting custom commands.
Exploitation of this vulnerability could lead to unauthorized script execution on the server.
Users are advised to upgrade to Apache HertzBeat version 1.7.3 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.