Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4157-1 | request-tracker4 security update |
Debian DSA |
DSA-5909-1 | request-tracker5 security update |
Debian DSA |
DSA-5911-1 | request-tracker4 security update |
EUVD |
EUVD-2024-31853 | Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination. |
Ubuntu USN |
USN-7692-1 | Request Tracker vulnerabilities |
Solution
Vulnerability fixed by applying the following patches: https://github.com/bestpractical/rt/commit/ea07e767eaef5b202e8883051616d09806b8b48a.patch and https://github.com/bestpractical/rt/commit/468f86bd3e82c3b5b5ef7087d416a7509d4b1abe.patch . In future versions of RT, this solution will be included as a configurable option of the tool.
Workaround
No workaround given by the vendor.
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:05:08.290Z
Reserved: 2024-04-03T09:53:11.218Z
Link: CVE-2024-3262
Updated: 2024-08-01T20:05:08.290Z
Status : Awaiting Analysis
Published: 2024-04-04T10:15:09.880
Modified: 2024-11-21T09:29:16.217
Link: CVE-2024-3262
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:10Z
Debian DLA
Debian DSA
EUVD
Ubuntu USN