OpenProject versions before 12.5.6 generate a publicly accessible robots.txt file revealing project identifiers, even if the instance is set to 'Login required', letting attackers gather project info, exploit requires no authentication.
id: CVE-2023-33960
info:
name: OpenProject < 12.5.4 - Project Identifiers Exposure
author: 0x_A
...