Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
References
Link | Resource |
---|---|
https://bugs.debian.org/911842 | Issue Tracking Mailing List Patch Third Party Advisory |
https://telescoper.wordpress.com/2018/10/18/a-breakthrough-for-a-bigot/#comment-339386 | Not Applicable |
Configurations
History
No history.
Information
Published : 2018-10-26 00:29
Updated : 2024-02-04 20:03
NVD link : CVE-2018-18655
Mitre link : CVE-2018-18655
CVE.ORG link : CVE-2018-18655
JSON object : View
Products Affected
prayer_project
- prayer
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor