CVE-2025-48927 Information
May 29, 2025
cve
Description
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI as exploited in the wild in May 2025.
Reference
https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes/
Share on: