Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Best Practical Request Tracker 信息泄露漏洞
Vulnerability Description
Best Practical Request Tracker是一款使用Perl语言编写的事件跟踪系统。 Best Practical Request Tracker 中存在信息泄露漏洞,该漏洞源于产品未对lib/RT/REST2/Middleware/Auth.pm文件安全管理。攻击者可通过发送定时攻击导致敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A