PT-2025-37098 · Hoverfly · Hoverfly
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Hoverfly versions 1.11.3 and prior
Description:
Hoverfly’s admin WebSocket endpoint
/api/v2/ws/logs lacks the authentication middleware present in the REST admin API. This allows an unauthenticated remote attacker to stream real-time application logs, potentially exposing sensitive data such as internal file paths and request/response bodies.Recommendations:
Update to version 1.12.0 or later.
Exploit
Fix
Information Disclosure
Improper Authentication
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoverfly