core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hashsalt is fileget_contents of a file that does not exist.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45440.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2023-05-09" } ] } ]