We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-48024



Description

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

Reserved 2025-05-15 | Published 2025-05-15 | Updated 2025-05-15 | Assigner mitre


MEDIUM: 5.0CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

Product status

Default status
unaffected

Any version before 2.1
affected

References

github.com/bluewave-labs/Checkmate/pull/2227

github.com/...ommit/7a855ef47adf2265121c236097059c7c6555fd7c

github.com/...ommit/91c2f7f0d5106bdfd4a0ff2c14b7e44acc3baee6

github.com/...ommit/36d78a9aa4ed607ca1bd2b5fdaca5a3927b2d287

github.com/...ckmate/security/advisories/GHSA-jjmg-cjr4-439m

cve.org (CVE-2025-48024)

nvd.nist.gov (CVE-2025-48024)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-48024

Support options

Helpdesk Chat, Email, Knowledgebase