ID: 14509
Title: add authentication to REST API documentation
Component: REST API
Level: 1
Class: Security fix
Version: 2.2.0i1
It was previously not required to be authenticated to access the site's REST API
documentation.
Because custom user tags and comments may appear in the automatically generated
documentation,
this would represent an "information leak". Therefore, from this Werk onwards,
the site's
REST API documentation is only allowed to be accessed by logged in users.
Vulnerability Management: We have rated the issue with a CVSS Score of 5.3 (Medium) with
the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. A CVE has been
requested