The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23409.json"