In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.1"
}
]
}