We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
Reserved 2025-05-15 | Published 2025-05-15 | Updated 2025-05-15 | Assigner mitreCWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
github.com/bluewave-labs/Checkmate/pull/2227
github.com/...ommit/7a855ef47adf2265121c236097059c7c6555fd7c
github.com/...ommit/91c2f7f0d5106bdfd4a0ff2c14b7e44acc3baee6
github.com/...ommit/36d78a9aa4ed607ca1bd2b5fdaca5a3927b2d287
github.com/...ckmate/security/advisories/GHSA-jjmg-cjr4-439m
Support options