Medium severity5.0NVD Advisory· Published May 15, 2025· Updated Apr 15, 2026
CVE-2025-48024
CVE-2025-48024
Description
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
Patches
536d78a9aa4ed7a855ef47adf91c2f7f0d510915a2b30b8471c02c15c049fVulnerability mechanics
Synthesis attempt was rejected by the grounding validator. Re-run pending.
References
5- github.com/bluewave-labs/Checkmate/commit/36d78a9aa4ed607ca1bd2b5fdaca5a3927b2d287nvd
- github.com/bluewave-labs/Checkmate/commit/7a855ef47adf2265121c236097059c7c6555fd7cnvd
- github.com/bluewave-labs/Checkmate/commit/91c2f7f0d5106bdfd4a0ff2c14b7e44acc3baee6nvd
- github.com/bluewave-labs/Checkmate/pull/2227nvd
- github.com/bluewave-labs/Checkmate/security/advisories/GHSA-jjmg-cjr4-439mnvd
News mentions
0No linked articles in our index yet.