CVE-2023-51389

CVSS V2 None CVSS V3 None
Description
Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixes this vulnerability.
Overview
  • CVE ID
  • CVE-2023-51389
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-22T15:59:29.842Z
  • Last Modified Date
  • 2024-02-22T15:59:29.842Z
History
Created Old Value New Value Data Type Notes
2024-06-24 18:45:58 Added to TrackCVE