PT-2015-5140 · Best Practical · Rt

Christian Loos

·

Published

2015-02-26

·

Updated

2017-09-03

·

CVE-2015-1165

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RT (aka Request Tracker) versions 3.8.8 through 4.0.22 RT (aka Request Tracker) versions 4.2.x before 4.2.10
Description The issue allows remote attackers to obtain sensitive RSS feed URLs and ticket data.
Recommendations For RT (aka Request Tracker) versions 3.8.8 through 4.0.22, update to version 4.0.23 or later. For RT (aka Request Tracker) versions 4.2.x before 4.2.10, update to version 4.2.10 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1165
DLA-158-1
DSA-3176-1
MGASA-2017-0325

Affected Products

Rt