Vulnerability Description
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/bluewave-labs/Checkmate/commit/36d78a9aa4ed607ca1bd2b5fdaca5a
- https://github.com/bluewave-labs/Checkmate/commit/7a855ef47adf2265121c236097059c
- https://github.com/bluewave-labs/Checkmate/commit/91c2f7f0d5106bdfd4a0ff2c14b7e4
- https://github.com/bluewave-labs/Checkmate/pull/2227
- https://github.com/bluewave-labs/Checkmate/security/advisories/GHSA-jjmg-cjr4-43
FAQ
What is CVE-2025-48024?
CVE-2025-48024 is a vulnerability with a CVSS score of 5.0 (MEDIUM). In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
How severe is CVE-2025-48024?
CVE-2025-48024 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-48024?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.