PT-2026-60791 · Thehive+1 · Thehive
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TheHive versions prior to 4.1.25
Description
An unauthenticated information disclosure issue exists where attackers can retrieve sensitive configuration data by sending a GET request to the '/api/status' endpoint. This occurs because the
StatusCtrl.scala handler fails to enforce authentication. Exposed data includes the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles.Recommendations
Update to version 4.1.25 or later.
As a temporary mitigation, restrict access to the '/api/status' endpoint.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thehive