5.9
CVE-2017-5361
- EPSS 0.36%
- Published 03.07.2017 16:29:00
- Last modified 20.04.2025 01:37:25
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-channel attack.
Data is provided by the National Vulnerability Database (NVD)
Bestpractical ≫ Request Tracker Version4.0.0
Bestpractical ≫ Request Tracker Version4.0.1
Bestpractical ≫ Request Tracker Version4.0.2
Bestpractical ≫ Request Tracker Version4.0.3
Bestpractical ≫ Request Tracker Version4.0.4
Bestpractical ≫ Request Tracker Version4.0.5
Bestpractical ≫ Request Tracker Version4.0.6
Bestpractical ≫ Request Tracker Version4.0.7
Bestpractical ≫ Request Tracker Version4.0.8
Bestpractical ≫ Request Tracker Version4.0.9
Bestpractical ≫ Request Tracker Version4.0.10
Bestpractical ≫ Request Tracker Version4.0.11
Bestpractical ≫ Request Tracker Version4.0.12
Bestpractical ≫ Request Tracker Version4.0.13
Bestpractical ≫ Request Tracker Version4.0.14
Bestpractical ≫ Request Tracker Version4.0.15
Bestpractical ≫ Request Tracker Version4.0.16
Bestpractical ≫ Request Tracker Version4.0.17
Bestpractical ≫ Request Tracker Version4.0.18
Bestpractical ≫ Request Tracker Version4.0.19
Bestpractical ≫ Request Tracker Version4.0.20
Bestpractical ≫ Request Tracker Version4.0.21
Bestpractical ≫ Request Tracker Version4.0.22
Bestpractical ≫ Request Tracker Version4.0.23
Bestpractical ≫ Request Tracker Version4.0.24
Bestpractical ≫ Request Tracker Version4.2.0
Bestpractical ≫ Request Tracker Version4.2.1
Bestpractical ≫ Request Tracker Version4.2.2
Bestpractical ≫ Request Tracker Version4.2.3
Bestpractical ≫ Request Tracker Version4.2.4
Bestpractical ≫ Request Tracker Version4.2.5
Bestpractical ≫ Request Tracker Version4.2.6
Bestpractical ≫ Request Tracker Version4.2.7
Bestpractical ≫ Request Tracker Version4.2.8
Bestpractical ≫ Request Tracker Version4.2.9
Bestpractical ≫ Request Tracker Version4.2.10
Bestpractical ≫ Request Tracker Version4.2.11
Bestpractical ≫ Request Tracker Version4.2.12
Bestpractical ≫ Request Tracker Version4.2.13
Bestpractical ≫ Request Tracker Version4.4.0
Bestpractical ≫ Request Tracker Version4.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.36% | 0.55 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|