Severity: Critical
CVSS Score: 9.1
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes