Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| trac(PyPI) | 0 | 0.10.3.1 | N/A |
CVSS Metrics