Apiman vulnerable to permissions bypass due to missing check on API key URL (CVE-2023-28640) | HOL Guard CVE