CVE Vulnerabilities

CVE-2023-41259

Published: Nov 03, 2023 | Modified: Nov 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

Affected Software

NameVendorStart VersionEnd Version
Request_trackerBestpractical*4.4.7 (excluding)
Request_trackerBestpractical5.0.0 (including)5.0.5 (excluding)
Request-tracker4Ubuntubionic*
Request-tracker4Ubuntuesm-apps/bionic*
Request-tracker4Ubuntuesm-apps/focal*
Request-tracker4Ubuntuesm-apps/jammy*
Request-tracker4Ubuntuesm-apps/xenial*
Request-tracker4Ubuntufocal*
Request-tracker4Ubuntujammy*
Request-tracker4Ubuntulunar*
Request-tracker4Ubuntumantic*
Request-tracker4Ubuntutrusty*
Request-tracker4Ubuntuupstream*
Request-tracker4Ubuntuxenial*
Request-tracker5Ubuntubionic*
Request-tracker5Ubuntuesm-apps/jammy*
Request-tracker5Ubuntujammy*
Request-tracker5Ubuntulunar*
Request-tracker5Ubuntumantic*
Request-tracker5Ubuntutrusty*
Request-tracker5Ubuntuupstream*
Request-tracker5Ubuntuxenial*

References