Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-57266

Опубликовано: 29 сент. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.

EPSS

Процентиль: 40%
0.00187
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.

EPSS

Процентиль: 40%
0.00187
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284