Authorizations are not properly verified when displaying the content of tracker report renderer and chart widgets.
Impact
Malicious users could use this vulnerability to retrieve the name of tracker they cannot access as well as the name of the fields used in reports.
CVSSv3.1 score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Exploitation
In a personal dashboard add a tracker report renderer widget using the ID of a renderer located in a tracker you cannot access.
References
CWE 285
CVE-2022-24896