It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.
CVE: (none) => CVE-2017-5361
We don't have this package.
Status: NEW => RESOLVEDResolution: (none) => INVALID