Lack of data validation - Path Traversal In request-tracker4
Description
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 4.2.8-3 | ||
debian 12 | 4.2.8-3 |
Aliases
1. 2. 3. 4. 5.