The homepage of the application is public which enables a guest to download the package which might contain sensitive information.
1.11.7
The access to the page can be manually restricted to a specific set of users or groups.
{
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"nvd_published_at": "2025-03-07T17:15:22Z",
"github_reviewed": true,
"github_reviewed_at": "2025-03-07T16:19:25Z"
}