Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4157-1 request-tracker4 security update
Debian DSA Debian DSA DSA-5909-1 request-tracker5 security update
Debian DSA Debian DSA DSA-5911-1 request-tracker4 security update
EUVD EUVD EUVD-2024-31853 Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.
Ubuntu USN Ubuntu USN USN-7692-1 Request Tracker vulnerabilities
Fixes

Solution

Vulnerability fixed by applying the following patches: https://github.com/bestpractical/rt/commit/ea07e767eaef5b202e8883051616d09806b8b48a.patch and https://github.com/bestpractical/rt/commit/468f86bd3e82c3b5b5ef7087d416a7509d4b1abe.patch . In future versions of RT, this solution will be included as a configurable option of the tool.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T20:05:08.290Z

Reserved: 2024-04-03T09:53:11.218Z

Link: CVE-2024-3262

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.290Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-04T10:15:09.880

Modified: 2024-11-21T09:29:16.217

Link: CVE-2024-3262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:10Z