As per our self-discovered vulnerability disclosure, we have just published the security advisory for [Security] Fix private profile setting leaking username on /json endpoint
Affected software
LINK
github.com
Affected software
- Chevereto >= 3.7.5, < 4.5.4 (patched)
- rodber/chevereto-free >= 1.0.0
LINK
Private profile setting leaking username on /json endpoint
### Impact When a user enables the private profile option, visiting their profile HTML route (`/username`) correctly returns 404. However, the `/json` AJAX listing endpoint does not apply the same...