Lucene search

K
nvd[email protected]NVD:CVE-2017-5361
HistoryJul 03, 2017 - 4:29 p.m.

CVE-2017-5361

2017-07-0316:29:00
web.nvd.nist.gov
8

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

66.1%

Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.

Affected configurations

Nvd
Node
bestpracticalrequest_trackerMatch4.0.0
OR
bestpracticalrequest_trackerMatch4.0.1
OR
bestpracticalrequest_trackerMatch4.0.2
OR
bestpracticalrequest_trackerMatch4.0.3
OR
bestpracticalrequest_trackerMatch4.0.4
OR
bestpracticalrequest_trackerMatch4.0.5
OR
bestpracticalrequest_trackerMatch4.0.6
OR
bestpracticalrequest_trackerMatch4.0.7
OR
bestpracticalrequest_trackerMatch4.0.8
OR
bestpracticalrequest_trackerMatch4.0.9
OR
bestpracticalrequest_trackerMatch4.0.10
OR
bestpracticalrequest_trackerMatch4.0.11
OR
bestpracticalrequest_trackerMatch4.0.12
OR
bestpracticalrequest_trackerMatch4.0.13
OR
bestpracticalrequest_trackerMatch4.0.14
OR
bestpracticalrequest_trackerMatch4.0.15
OR
bestpracticalrequest_trackerMatch4.0.16
OR
bestpracticalrequest_trackerMatch4.0.17
OR
bestpracticalrequest_trackerMatch4.0.18
OR
bestpracticalrequest_trackerMatch4.0.19
OR
bestpracticalrequest_trackerMatch4.0.20
OR
bestpracticalrequest_trackerMatch4.0.21
OR
bestpracticalrequest_trackerMatch4.0.22
OR
bestpracticalrequest_trackerMatch4.0.23
OR
bestpracticalrequest_trackerMatch4.0.24
OR
bestpracticalrequest_trackerMatch4.2.0
OR
bestpracticalrequest_trackerMatch4.2.1
OR
bestpracticalrequest_trackerMatch4.2.2
OR
bestpracticalrequest_trackerMatch4.2.3
OR
bestpracticalrequest_trackerMatch4.2.4
OR
bestpracticalrequest_trackerMatch4.2.5
OR
bestpracticalrequest_trackerMatch4.2.6
OR
bestpracticalrequest_trackerMatch4.2.7
OR
bestpracticalrequest_trackerMatch4.2.8
OR
bestpracticalrequest_trackerMatch4.2.9
OR
bestpracticalrequest_trackerMatch4.2.10
OR
bestpracticalrequest_trackerMatch4.2.11
OR
bestpracticalrequest_trackerMatch4.2.12
OR
bestpracticalrequest_trackerMatch4.2.13
OR
bestpracticalrequest_trackerMatch4.4.0
OR
bestpracticalrequest_trackerMatch4.4.1
VendorProductVersionCPE
bestpracticalrequest_tracker4.0.0cpe:2.3:a:bestpractical:request_tracker:4.0.0:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.1cpe:2.3:a:bestpractical:request_tracker:4.0.1:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.2cpe:2.3:a:bestpractical:request_tracker:4.0.2:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.3cpe:2.3:a:bestpractical:request_tracker:4.0.3:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.4cpe:2.3:a:bestpractical:request_tracker:4.0.4:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.5cpe:2.3:a:bestpractical:request_tracker:4.0.5:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.6cpe:2.3:a:bestpractical:request_tracker:4.0.6:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.7cpe:2.3:a:bestpractical:request_tracker:4.0.7:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.8cpe:2.3:a:bestpractical:request_tracker:4.0.8:*:*:*:*:*:*:*
bestpracticalrequest_tracker4.0.9cpe:2.3:a:bestpractical:request_tracker:4.0.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 411

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.9

Confidence

High

EPSS

0.003

Percentile

66.1%