CVE-2024-49395
MEDIUMDescription
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Is your site exposed to CVE-2024-49395?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mutt | mutt |
| neomutt | neomutt |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
References
Frequently Asked Questions
What is CVE-2024-49395? +
How severe is CVE-2024-49395? +
What products are affected by CVE-2024-49395? +
How do I check if I'm vulnerable to CVE-2024-49395? +
Related Vulnerabilities
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed …
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to …
The users endpoint in the groov View API returns a list of all users and associated metadata including their API …
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while …
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could …