5
CVSSv2

CVE-2012-2770

Published: 15/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Authen::ExternalAuth extension prior to 0.11 for Best Practical Solutions RT allows remote malicious users to obtain a logged-in session via unspecified vectors related to the "URL of a RSS feed of the user."

Vulnerable Product Search on Vulmon Subscribe to Product

mike_peachey authen\\ \\

Vendor Advisories

Debian Bug report logs - #683288 rt-authen-externalauth: privilege escalation Package: rt-authen-externalauth; Maintainer for rt-authen-externalauth is Tom Jampen <tom@cryptographych>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Mon, 30 Jul 2012 14:57:01 UTC Severity: grave Tags: security Fixed in vers ...