CVE-2013-3370Request-tracker4 vulnerability

CWE-2645 documents5 sources
Severity
6.8MEDIUMNVD
EPSS
1.1%
top 21.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 17

Description

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attackers to have an unspecified impact via a direct request.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

debiandebian/request-tracker4< request-tracker4 4.0.12-2 (bookworm)
NVDbestpractical/rt30 versions+29

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7chq-pmg6-6mv3: Request Tracker (RT) 32022-05-17
OSV
CVE-2013-3370: Request Tracker (RT) 32013-08-23

📋Vendor Advisories

1
Debian
CVE-2013-3370: request-tracker4 - Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not proper...2013
CVE-2013-3370 — Debian Request-tracker4 vulnerability | cvebase