Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-41259
HistoryNov 03, 2023 - 12:00 a.m.

CVE-2023-41259

2023-11-0300:00:00
mitre
github.com
request tracker
information disclosure
email headers
mail-gateway
rest api

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:best_practical_solutions:request_tracker:*:*:*:*:*:*:*:*"
    ],
    "vendor": "best_practical_solutions",
    "product": "request_tracker",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "4.4.7",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "5x",
        "lessThan": "5.0.5",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial