PT-2013-1715 · Best Practical · Request Tracker
Publicado
2013-08-23
·
Atualizado
2017-09-03
·
CVE-2012-4733
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Request Tracker (RT) versions 4.0.0 through 4.0.12
Description
The issue concerns the improper enforcement of the DeleteTicket and custom lifecycle transition permission. This allows remote authenticated users with the ModifyTicket permission to delete tickets.
Recommendations
For versions 4.0.0 through 4.0.12, update to version 4.0.13 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Request Tracker