{"id":"GHSA-h6w8-27ph-c385","aliases":[],"url":"https://o3.security/vulnerability/GHSA-h6w8-27ph-c385","summary":" Leantime has Insufficiently Protected Credentials","details":"Due to improper cache control an attacker can view sensitive information even if they are not logged into the account anymore.\n\nAdditional Information:\n\n    1.The issue was identified during routine security testing.\n    2.This vulnerability poses a significant risk to user privacy and data security.\n    3.Urgent action is recommended to mitigate this vulnerability and protect user data from unauthorized access.","published":"2025-02-21T22:15:19Z","modified":"2025-02-21T22:26:17.882589Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"leantime/leantime","fixedVersion":"3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Leantime/leantime/security/advisories/GHSA-h6w8-27ph-c385"},{"type":"PACKAGE","url":"https://github.com/Leantime/leantime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-21T22:26:17.882589Z"}}