CVE-2007-1406: Trac missing Content-Disposition HTTP header
(updated )
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain “unsafe” situations, which has unknown impact and remote attack vectors.
References
Detect and mitigate CVE-2007-1406 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →