Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
References
Link | Resource |
---|---|
https://bugs.debian.org/911842 | Issue Tracking Mailing List Patch Third Party Advisory |
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 | Not Applicable |
https://bugs.debian.org/911842 | Issue Tracking Mailing List Patch Third Party Advisory |
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 | Not Applicable |
Configurations
History
21 Nov 2024, 03:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.debian.org/911842 - Issue Tracking, Mailing List, Patch, Third Party Advisory | |
References | () https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 - Not Applicable |
Information
Published : 2018-10-26 00:29
Updated : 2024-11-21 03:56
NVD link : CVE-2018-18655
Mitre link : CVE-2018-18655
CVE.ORG link : CVE-2018-18655
JSON object : View
Products Affected
prayer_project
- prayer
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor