CVE-2025-52493: Infoleak
PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52493?
The severity of CVE-2025-52493 is considered high due to exposed stored secrets in the web application.
How do I fix CVE-2025-52493?
To fix CVE-2025-52493, upgrade to the latest version of PagerDuty Runbook released after June 12, 2025.
What types of secrets are exposed in CVE-2025-52493?
CVE-2025-52493 exposes sensitive information such as passwords stored in the webpage DOM.
Who is affected by CVE-2025-52493?
Users of PagerDuty Runbook versions up to and including 2025-06-12 are affected by CVE-2025-52493.
Is CVE-2025-52493 a critical vulnerability?
Yes, CVE-2025-52493 is classified as a critical vulnerability due to potential unauthorized access to sensitive information.