VYPR
High severity7.5NVD Advisory· Published Aug 20, 2024· Updated Jun 17, 2026

CVE-2024-42361

CVE-2024-42361

Description

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apache/HertzBeat2 versions
    cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*range: <1.6.0
    • (no CPE)range: <= 1.6.0
  • Range: <=1.6.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.