Improper authorization control for web services In request-tracker4
Description
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 4.0.12-2 | ||
debian 11 | 4.0.12-2 |
Aliases
1. 2. 3. 4. 5.