The homepage of the application is public which enables a guest to download the package which might contain sensitive information.
1.11.7
The access to the page can be manually restricted to a specific set of users or groups.
{ "nvd_published_at": "2025-03-07T17:15:22Z", "github_reviewed_at": "2025-03-07T16:19:25Z", "severity": "HIGH", "cwe_ids": [ "CWE-200" ], "github_reviewed": true }