Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-52493

Опубликовано: 10 дек. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pagerduty:runbook_automation:*:*:*:*:*:*:*:*
Версия до 2025-06-12 (включая)

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
github
около 2 месяцев назад

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200