PT-2024-24728 · Rt+3 · Rt+3
Javier Garcia Antón
·
Published
2024-04-04
·
Updated
2025-08-13
·
CVE-2024-3262
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RT software version 4.4.1
Description
The issue allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets. This is because the application stores the information in the browser cache, leading to information exposure despite session termination.
Recommendations
For RT software version 4.4.1, consider clearing the browser cache after each session to minimize the risk of information exposure. As a temporary workaround, restrict local access to the device to prevent potential attackers from retrieving sensitive information.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Rt
Ubuntu