Leantime has Insufficiently Protected Credentials
Moderate severity
GitHub Reviewed
Published
Feb 18, 2025
in
Leantime/leantime
•
Updated Feb 21, 2025
Description
Published to the GitHub Advisory Database
Feb 21, 2025
Reviewed
Feb 21, 2025
Last updated
Feb 21, 2025
Due to improper cache control an attacker can view sensitive information even if they are not logged into the account anymore.
Additional Information:
References