In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-33913.json"