4.3
CVSSv3

CVE-2018-18655

Published: 26/10/2018 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Prayer up to and including 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prayer project prayer

Vendor Advisories

Debian Bug report logs - #911842 prayer: CVE-2018-18655: Information disclosure via Referrer: header Package: prayer; Maintainer for prayer is Magnus Holmgren <holmgren@debianorg>; Source for prayer is src:prayer (PTS, buildd, popcon) Reported by: Matthew Vernon <matthew@debianorg> Date: Thu, 25 Oct 2018 11:42:02 U ...