Users with no system permissions are able to see and create personal access tokens
{
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-284",
"CWE-862"
],
"nvd_published_at": "2022-01-13T23:15:00Z",
"github_reviewed_at": "2022-01-24T22:48:49Z"
}