CVE-2012-4733
published 2013-08-23CVE-2012-4733: Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote…
PriorityP430medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.63%
73.3th percentile
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| debian | request-tracker4 | < request-tracker4 4.0.12-2 (bookworm) | request-tracker4 4.0.12-2 (bookworm) |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3f39-v4r2-mjqq: Request Tracker (RT) 4
ghsa_unreviewed·2022-05-17
CVE-2012-4733 [MEDIUM] GHSA-3f39-v4r2-mjqq: Request Tracker (RT) 4
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
OSV
CVE-2012-4733: Request Tracker (RT) 4
osv·2013-08-23·CVSS 6.0
CVE-2012-4733 [MEDIUM] CVE-2012-4733: Request Tracker (RT) 4
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Debian
CVE-2012-4733: request-tracker4 - Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicke...
vendor_debian·2012·CVSS 6.0
CVE-2012-4733 [MEDIUM] CVE-2012-4733: request-tracker4 - Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicke...
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.0.12-2)
bullseye: resolved (fixed in 4.0.12-2)
sid: resolved (fixed in 4.0.12-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlhttp://secunia.com/advisories/53522http://www.osvdb.org/93611http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlhttp://secunia.com/advisories/53522http://www.osvdb.org/93611
2013-08-23
Published