Using a carefully crafted request, a backend user could determine the API credentials of another user.
CiviCRM version 5.24.2 and earlier
CiviCRM version 5.24.3 and 5.21.3
Upgrade to the latest version of CiviCRM
Patrick Figel (Greenpeace CEE) for reporting the issue
Patrick Figel (Greenpeace CEE) and Eileen McNaughton (Wikimedia Foundation) for resolving the issue