CVE-2025-48927
CVE-2025-48927
In short
TeleMessage exposes a heap dump endpoint through Spring Boot Actuator, allowing attackers to download memory snapshots that may contain sensitive data like passwords and tokens.
Technical detail
The Spring Boot Actuator /heapdump endpoint is publicly accessible without authentication, enabling remote attackers to retrieve heap dumps containing sensitive information from application memory. This CWE-1188 issue affects TeleMessage versions through 2025-05-05 and has been exploited in the wild.
Summary generated and translated by AI from the official description.
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
TeleMessage · serviceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →