CVE-2025-48208

CVE-2025-48208: Apache HertzBeat (incubating): Jmx JNDI injection vulnerability

Vendor Apache Software Foundation
Product Apache HertzBeat (incubating)
Weakness CWE-90 · LDAP injection
Published September 9, 2025
Last update November 4, 2025

CVSS base score

What the vulnerability does

Description

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom commands. A successful attack would result in arbitrary script execution. This issue affects Apache HertzBeat: through 1.7.2. Users are recommended to upgrade to version [1.7.3], which fixes the issue.

Key dates

Disclosure timeline

September 9, 2025 CVE published
November 4, 2025 Record updated