Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
{
"nvd_published_at": "2017-11-10T02:29:00Z",
"severity": "MODERATE",
"github_reviewed_at": "2024-04-23T23:16:04Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-732"
]
}