CVE-2012-4733Request-tracker4 vulnerability

CWE-2554 documents4 sources
Severity
6.0MEDIUMNVD
EPSS
0.6%
top 31.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 17

Description

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages2 packages

debiandebian/request-tracker4< request-tracker4 4.0.12-2 (bookworm)
NVDbestpractical/rt7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3f39-v4r2-mjqq: Request Tracker (RT) 42022-05-17
OSV
CVE-2012-4733: Request Tracker (RT) 42013-08-23

📋Vendor Advisories

1
Debian
CVE-2012-4733: request-tracker4 - Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicke...2012
CVE-2012-4733 — Debian Request-tracker4 vulnerability | cvebase