Vendor
Devtron versions 2.2.0 and earlier contain an authorization flaw in the orchestrator webhook endpoint that allows authenticated users to retrieve plaintext super-admin API tokens.