CVE-2012-4734Confused Deputy in Request-tracker4

CWE-2646 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.2%
top 63.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 17

Description

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to a crafted link.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

debiandebian/request-tracker4< request-tracker4 4.0.7-2 (bookworm)
NVDbestpractical/rt24 versions+23

🔴Vulnerability Details

2
GHSA
GHSA-jcrf-hc42-gp7c: Request Tracker (RT) 32022-05-17
OSV
CVE-2012-4734: Request Tracker (RT) 32012-11-11

📋Vendor Advisories

1
Debian
CVE-2012-4734: request-tracker4 - Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote at...2012

💬Community

2
Bugzilla
CVE-2012-4730 CVE-2012-4732 CVE-2012-4734 CVE-2012-4735 CVE-2012-4884 rt3: Multiple flaws fixed in upstream 3.8.15 version [fedora-all]2012-10-26
Bugzilla
CVE-2012-4730 CVE-2012-4732 CVE-2012-4734 CVE-2012-4735 CVE-2012-4884 rt3: Multiple flaws fixed in upstream 3.8.15 version [epel-all]2012-10-26
CVE-2012-4734 — Confused Deputy in Request-tracker4 | cvebase