cve/2024/CVE-2024-42323.md

33 lines
1.4 KiB
Markdown
Raw Normal View History

2025-09-29 16:08:36 +00:00
### [CVE-2024-42323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42323)
![](https://img.shields.io/static/v1?label=Product&message=Apache%20HertzBeat&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%201.6.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-502%20Deserialization%20of%20Untrusted%20Data&color=brighgreen)
### Description
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers.This issue affects Apache HertzBeat (incubating): before 1.6.0.Users are recommended to upgrade to version 1.6.0, which fixes the issue.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/12442RF/POC
- https://github.com/1diot9/MyJavaSecStudy
- https://github.com/DMW11525708/wiki
- https://github.com/J1ezds/Vulnerability-Wiki-page
- https://github.com/Lern0n/Lernon-POC
- https://github.com/Linxloop/fork_POC
- https://github.com/Threekiii/Awesome-POC
- https://github.com/adysec/POC
- https://github.com/eeeeeeeeee-code/POC
- https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
- https://github.com/greenberglinken/2023hvv_1
- https://github.com/iemotion/POC
- https://github.com/laoa1573/wy876
- https://github.com/oLy0/Vulnerability
- https://github.com/plbplbp/loudong001
- https://github.com/yulate/yulate