Apache HertzBeat是美国阿帕奇(Apache)公司的一个可以监控各种组件的工具。 Apache HertzBeat 1.8.0之前版本存在安全漏洞,该漏洞源于XPath表达式数据中和不当,可能导致XPath注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache HertzBeat | 1.7.1 ~ 1.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-23906 | Apache Druid: Authentication Bypass via LDAP Anonymous Bind | |
| CVE-2026-23901 | Apache Shiro: Brute force attack possible to determine valid user names |
No comments yet