VDB
CVE-2023-41259
CVE-2023-41259
PUBLISHED
CVSS 7.5 HIGH
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
EPSS 0.14% · 33.2th percentile
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.14%
33.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| best_practical_solutions | request_tracker | 0, 5x |
| n/a | n/a | n/a |
| bestpractical | request_tracker | 0, 5.0.0 |
Timeline
- Nov 3, 2023 CVE Published
- Nov 3, 2023 EPSS Score
- Dec 4, 2023 EPSS Score
- Jan 3, 2024 EPSS Score
- Feb 3, 2024 EPSS Score
- Mar 4, 2024 EPSS Score
- Apr 4, 2024 EPSS Score
- May 5, 2024 EPSS Score
- Jun 4, 2024 EPSS Score
- Jul 5, 2024 EPSS Score
- Aug 4, 2024 EPSS Score
- Sep 4, 2024 EPSS Score
References
- https://docs.bestpractical.com/release-notes/rt/index.html url
- https://docs.bestpractical.com/release-notes/rt/5.0.5 url
- https://docs.bestpractical.com/release-notes/rt/4.4.7 url
- https://lists.debian.org/debian-lts-announce/2023/10/msg00046.html url
- https://nvd.nist.gov/vuln/detail/CVE-2023-41259 advisory