Home
MEDIUM: 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
Any version before 2.1
affected
Description
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Any version before 2.1
References
github.com/bluewave-labs/Checkmate/pull/2227
github.com/...ommit/7a855ef47adf2265121c236097059c7c6555fd7c
github.com/...ommit/91c2f7f0d5106bdfd4a0ff2c14b7e44acc3baee6
github.com/...ommit/36d78a9aa4ed607ca1bd2b5fdaca5a3927b2d287
github.com/...ckmate/security/advisories/GHSA-jjmg-cjr4-439m