An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB0750906 | vendor advisory patch |
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1001612 | vendor advisory patch |
https://www.vulncheck.com/advisories/sitecore-jss-react-sample-application-info-disc | third party advisory |