Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Link | Tags |
---|---|
https://www.drupal.org/sa-contrib-2024-033 | third party advisory |