Insecure session expiration time In request-tracker4
Description
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 4.2.8-3 | ||
debian 12 | 4.2.8-3 |
Aliases
1. 2. 3. 4. 5.