CVE-2025-48741

MEDIUM

StrangeBee TheHive <5.2.16-5.3.11-5.4.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.

Scores

CVSS v4 6.8
EPSS 0.0027
EPSS Percentile 18.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (3)
StrangeBee/TheHive 5.2.0 - 5.2.16
StrangeBee/TheHive 5.3.0 - 5.3.11
StrangeBee/TheHive 5.4.0 - 5.4.10
Published May 23, 2025
Tracked Since Feb 18, 2026