Fides versions 2.19.0 to before 2.39.2rc0 contain an information disclosure caused by unauthenticated HTTP GET request to the Privacy Center, letting attackers access the SERVER_SIDE_FIDES_API_URL, which may reveal server configuration details, exploit requires no authentication.
id: CVE-2024-31223
info:
name: Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure
autho
...