Impact
An authenticated but non‑administrative user can invoke the REST 2.0 collection endpoint for users and obtain plain‑text credentials for any other user, including those with administrative privileges. The attacker then uses those credentials to act as those users—reading data, rotating credentials, and invalidating existing feed URLs—effectively achieving information disclosure and privilege escalation. The flaw corresponds to CWE‑200, CWE‑269 and CWE‑863.
Affected Systems
The bestpractical RT issue tracker is affected in all releases prior to 5.0.10 and prior to 6.0.3. Versions 5.0.10 and 6.0.3 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical impact. Exploitation requires an authenticated user with at least privileged (non‑administrative) rights and does not rely on network isolation. The attacker must call the REST 2.0 endpoint that lists user information; the response includes user credentials in plain text. Once captured, these credentials provide the attacker with the same access rights as the target user, including administrative privileges in the most severe cases. The vulnerability is not currently listed in CISA KEV, and the EPSS score of <1% indicates a very low probability of exploitation, but the high CVSS score still signals a critical severity if exploited.
OpenCVE Enrichment
Debian DSA
Ubuntu USN