CVE-2012-4733
23.08.2013, 16:55
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bestpractical | rt | 4.0.0 |
| bestpractical | rt | 4.0.0:rc1 |
| bestpractical | rt | 4.0.0:rc2 |
| bestpractical | rt | 4.0.0:rc3 |
| bestpractical | rt | 4.0.0:rc4 |
| bestpractical | rt | 4.0.0:rc5 |
| bestpractical | rt | 4.0.0:rc6 |
| bestpractical | rt | 4.0.0:rc7 |
| bestpractical | rt | 4.0.0:rc8 |
| bestpractical | rt | 4.0.1 |
| bestpractical | rt | 4.0.1:rc1 |
| bestpractical | rt | 4.0.1:rc2 |
| bestpractical | rt | 4.0.2 |
| bestpractical | rt | 4.0.2:rc1 |
| bestpractical | rt | 4.0.2:rc2 |
| bestpractical | rt | 4.0.3 |
| bestpractical | rt | 4.0.10 |
| bestpractical | rt | 4.0.11 |
| bestpractical | rt | 4.0.12 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| request-tracker3.8 |
| ||||||||||||||||||||||||
| request-tracker4 |
|
Common Weakness Enumeration
References