CVE-2025-24404

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:hertzbeat:*:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/09/06/4 -

Information

Published : 2025-09-09 10:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-24404

Mitre link : CVE-2025-24404

CVE.ORG link : CVE-2025-24404


JSON object : View

Products Affected

apache

  • hertzbeat
CWE
CWE-91

XML Injection (aka Blind XPath Injection)