core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
{
"github_reviewed_at": "2024-08-29T18:05:46Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-209",
"CWE-497"
],
"nvd_published_at": "2024-08-29T11:15:27Z"
}