GHSA-c448-w867-m9h4MediumCVSS 5.3
An authenticated Ops Manager organization member can retrieve another member's pending...
🔗 CVE IDs covered (1)
📋 Description
An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.