CPE
PasswordPusher versions prior to 2.11.1 contain a race condition in view limit enforcement, allowing unauthenticated attackers to bypass 'expire_after_views' restrictions and access one-time secrets multiple times through concurrent requests.