CVE-2011-1007
low
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
2.1
Description
Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| bestpractical | rt | {"endIncluding":"3.8.9"} | |
| bestpractical | rt | 1.0.0 | |
| bestpractical | rt | 1.0.1 | |
| bestpractical | rt | 1.0.2 | |
| bestpractical | rt | 1.0.3 | |
| bestpractical | rt | 1.0.4 | |
| bestpractical | rt | 1.0.5 | |
| bestpractical | rt | 1.0.6 | |
| bestpractical | rt | 1.0.7 | |
| bestpractical | rt | 2.0.0 | |
| bestpractical | rt | 2.0.1 | |
| bestpractical | rt | 2.0.2 | |
| bestpractical | rt | 2.0.3 | |
| bestpractical | rt | 2.0.4 | |
| bestpractical | rt | 2.0.5 | |
| bestpractical | rt | 2.0.5.1 | |
| bestpractical | rt | 2.0.5.3 | |
| bestpractical | rt | 2.0.6 | |
| bestpractical | rt | 2.0.7 | |
| bestpractical | rt | 2.0.8 | |
| bestpractical | rt | 2.0.8.2 | |
| bestpractical | rt | 2.0.9 | |
| bestpractical | rt | 2.0.11 | |
| bestpractical | rt | 2.0.12 | |
| bestpractical | rt | 2.0.13 | |
| bestpractical | rt | 2.0.14 | |
| bestpractical | rt | 2.0.15 | |
| bestpractical | rt | 3.0.0 | |
| bestpractical | rt | 3.0.1 | |
| bestpractical | rt | 3.0.2 | |
| bestpractical | rt | 3.0.3 | |
| bestpractical | rt | 3.0.4 | |
| bestpractical | rt | 3.0.5 | |
| bestpractical | rt | 3.0.6 | |
| bestpractical | rt | 3.0.7 | |
| bestpractical | rt | 3.0.7.1 | |
| bestpractical | rt | 3.0.8 | |
| bestpractical | rt | 3.0.9 | |
| bestpractical | rt | 3.0.10 | |
| bestpractical | rt | 3.0.11 | |
| bestpractical | rt | 3.0.12 | |
| bestpractical | rt | 3.2.0 | |
| bestpractical | rt | 3.2.1 | |
| bestpractical | rt | 3.2.2 | |
| bestpractical | rt | 3.2.3 | |
| bestpractical | rt | 3.4.0 | |
| bestpractical | rt | 3.4.1 | |
| bestpractical | rt | 3.4.2 | |
| bestpractical | rt | 3.4.3 | |
| bestpractical | rt | 3.4.4 | |
| bestpractical | rt | 3.4.5 | |
| bestpractical | rt | 3.4.6 | |
| bestpractical | rt | 3.6.0 | |
| bestpractical | rt | 3.6.1 | |
| bestpractical | rt | 3.6.2 | |
| bestpractical | rt | 3.6.3 | |
| bestpractical | rt | 3.6.4 | |
| bestpractical | rt | 3.6.5 | |
| bestpractical | rt | 3.6.6 | |
| bestpractical | rt | 3.6.7 | |
| bestpractical | rt | 3.6.8 | |
| bestpractical | rt | 3.6.9 | |
| bestpractical | rt | 3.8.0 | |
| bestpractical | rt | 3.8.1 | |
| bestpractical | rt | 3.8.2 | |
| bestpractical | rt | 3.8.3 | |
| bestpractical | rt | 3.8.4 | |
| bestpractical | rt | 3.8.5 | |
| bestpractical | rt | 3.8.6 | |
| bestpractical | rt | 3.8.7 | |
| bestpractical | rt | 3.8.8 | |
| bestpractical | rt | 3.8.9 | |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=614575
- http://issues.bestpractical.com/Ticket/Display.html?id=15804
- http://lists.bestpractical.com/pipermail/rt-announce/2011-February/000186.html
- http://openwall.com/lists/oss-security/2011/02/22/12
- http://openwall.com/lists/oss-security/2011/02/22/16
- http://openwall.com/lists/oss-security/2011/02/22/6
- http://openwall.com/lists/oss-security/2011/02/23/22
- http://openwall.com/lists/oss-security/2011/02/24/7
- http://openwall.com/lists/oss-security/2011/02/24/8
- http://openwall.com/lists/oss-security/2011/02/24/9
- http://osvdb.org/71012
- http://secunia.com/advisories/43438
- http://www.vupen.com/english/advisories/2011/0475
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65771
- https://github.com/bestpractical/rt/commit/057552287159e801535e59b8fbd5bd98d1322069
- https://github.com/bestpractical/rt/commit/917c211820590950f7eb0521f7f43b31aeed44c4
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=614575
- http://issues.bestpractical.com/Ticket/Display.html?id=15804
- http://lists.bestpractical.com/pipermail/rt-announce/2011-February/000186.html
- http://openwall.com/lists/oss-security/2011/02/22/12
- http://openwall.com/lists/oss-security/2011/02/22/16
- http://openwall.com/lists/oss-security/2011/02/22/6
- http://openwall.com/lists/oss-security/2011/02/23/22
- http://openwall.com/lists/oss-security/2011/02/24/7
CWEs
CWE-255
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.