Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rt-authen-externalauthUpgrade request-tracker4 | Jun 15, 2017 | Jun 15, 2017 |
| Freebsd | — | Upgrade rt44Upgrade rt42Upgrade p5-RT-Authen-ExternalAuth | Jun 16, 2017 | Jun 15, 2017 |
| Ubuntu | — | Upgrade rt-authen-externalauthUpgrade request-tracker4 | Nov 19, 2024 | Jul 3, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub