← back
CVE-2025-48927

CVE-2025-48927

CVSS 5.3 MEDIUMEPSS 7.9%● KEVCWE-1188
In short

TeleMessage exposes a heap dump endpoint through Spring Boot Actuator, allowing attackers to download memory snapshots that may contain sensitive data like passwords and tokens.

Technical detail

The Spring Boot Actuator /heapdump endpoint is publicly accessible without authentication, enabling remote attackers to retrieve heap dumps containing sensitive information from application memory. This CWE-1188 issue affects TeleMessage versions through 2025-05-05 and has been exploited in the wild.

Summary generated and translated by AI from the official description.
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
TeleMessage · service

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →