Our Settings are published to the client, even for anonymous users, and include the following fields:
- apiUmbrella
- elasticsearch url
These settings can be abused, so should be handled more carefully.
Steps to reproduce
- visit the home page as an anonymous user
- open the browser console
- search the Settings collection for a single document