A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.