Expected Findings
- Public config includes internal topology and flags.
- Debug config reveals environment and secret hints.
The page boot flow fetches two configuration endpoints that include internal hostnames, feature flags, and environment details not meant for the client.
CWE-200CWE-489
{"enableAdmin":true,"bypassRateLimit":true}