SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
{ "urgency": "not yet assigned" }