CNNVD-202509-1408 Information

CNNVD ID

CNNVD-202509-1408

CVE-2025-24404

  • CNNVD Published: 2025-09-09

Description (Chinese)

Apache HertzBeat是美国阿帕奇(Apache)公司的一个可以监控各种组件的工具。 Apache HertzBeat 1.7.0之前版本存在安全漏洞,该漏洞源于XML解析漏洞,可能导致远程代码执行。

Description (English)

Apache Hertz Beat is a tool for the United States company Apache to monitor various components. There was a security loophole in the pre-Apache Hertz Beat 1.7.0 version, which originated from an XML detachment that could lead to remote code implementation.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Apache Friends

Published

2025-09-09

Last Modified

2026-02-24

References

https://lists.apache.org/thread/4ydy3tqbpwmhl79mcj3pxwqz62nggrfd

Patch

https://hertzbeat.apache.org/zh-cn/docs/download/

Share on: