Unauthorized users are able to obtain sensitive information about the system's runtime environment, features they have no permissions to access, etc.
Update to version 10.6.4 or apply this patch manually https://github.com/pimcore/pimcore/commit/0237527b3244d251fa5ecd4912dfe4f8b2125c54.patch
Apply patch https://github.com/pimcore/pimcore/commit/0237527b3244d251fa5ecd4912dfe4f8b2125c54.patch manually.
https://huntr.dev/bounties/be5e4d4c-1b0b-4c01-a1fc-00533135817c/
{ "nvd_published_at": "2023-07-21T15:15:10Z", "cwe_ids": [ "CWE-200" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-21T20:18:22Z" }