An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-29860.json"