If there is indeed a way for a normal user (not an operator) of the environment to cause this information leak to happen and then take advantage of it, we should find a way to prevent at least that aspect before making this report public.
If it's not a condition that a normal user can intentionally cause to happen, then it's probably fine to fix this in public instead.
If there is indeed a way for a normal user (not an operator) of the environment to cause this information leak to happen and then take advantage of it, we should find a way to prevent at least that aspect before making this report public.
If it's not a condition that a normal user can intentionally cause to happen, then it's probably fine to fix this in public instead.