rdiffweb version 2.4.1 is set to a default and leaks error information. Version 2.4.2 fixes this issue.
{ "nvd_published_at": "2022-09-13T10:15:00Z", "github_reviewed_at": "2022-09-15T03:23:16Z", "github_reviewed": true, "severity": "MODERATE", "cwe_ids": [ "CWE-755", "CWE-756" ] }