Impact
The vulnerability arises when the global showURL setting is enabled, allowing an unauthenticated GET request to /api/v1/status-page/:url to return the full monitor object in JSON, including the secret field used as an HTTP Authorization credential. Attackers can read the bearer token from the response and use it to authenticate against monitored services, constituting a confidentiality breach and credential exposure.
Affected Systems
The affected product is Checkmate by bluewave‑labs. Versions from 3.3.0 up to but excluding 3.9.2 are impacted. The flaw is resolved in Checkmate 3.9.2 and later releases.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the flaw by accessing the public or internal /api/v1/status-page/:url endpoint without authentication; the exposed bearer token provides full access to monitored services.
OpenCVE Enrichment