PT-2025-53656 · Halo · Halo

Vuldb

+1

·

Published

2025-12-28

·

Updated

2026-02-19

·

CVE-2025-15141

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Halo versions up to 2.21.10
Description A flaw exists in Halo, specifically within the Configuration Handler component. This issue involves the processing of the /actuator file and can lead to information disclosure. The attack can be carried out remotely and is considered to be of high complexity with difficult exploitability. The exploit for this issue has been publicly disclosed. The vendor was informed about the disclosure but did not provide a response.
API Endpoints /actuator
Recommendations Versions prior to 2.21.10 should be updated. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-15141

Affected Products

Halo