CVE-2025-48741
EUVD-2025-2824823.05.2025, 20:15
A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| strangebee | thehive | 5.2.0 ≤ 𝑥 < 5.2.16 | CNA |
| strangebee | thehive | 5.3.0 ≤ 𝑥 < 5.3.11 | CNA |
| strangebee | thehive | 5.4.0 ≤ 𝑥 < 5.4.10 | CNA |
Common Weakness Enumeration