CVE-2023-41260
Ubuntu Security Notice USN-6529-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Best Practical Request Tracker (RT) anterior a 4.4.7 y 5.x anterior a 5.0.5 permite la exposición de información en respuestas a llamadas API REST de puerta de enlace de correo.
It was discovered that Request Tracker was susceptible to timing attacks. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious attachments were supplied. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-08-25 CVE Reserved
- 2023-10-31 CVE Published
- 2024-09-05 CVE Updated
- 2025-08-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.bestpractical.com/release-notes/rt/4.4.7 | 2023-11-13 | |
https://docs.bestpractical.com/release-notes/rt/5.0.5 | 2023-11-13 | |
https://docs.bestpractical.com/release-notes/rt/index.html | 2023-11-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bestpractical Search vendor "Bestpractical" | Request Tracker Search vendor "Bestpractical" for product "Request Tracker" | < 4.4.7 Search vendor "Bestpractical" for product "Request Tracker" and version " < 4.4.7" | - |
Affected
| ||||||
Bestpractical Search vendor "Bestpractical" | Request Tracker Search vendor "Bestpractical" for product "Request Tracker" | >= 5.0.0 < 5.0.5 Search vendor "Bestpractical" for product "Request Tracker" and version " >= 5.0.0 < 5.0.5" | - |
Affected
|