CVE-2010-5108: High severity edgewall trac vulnerability
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5108?
CVE-2010-5108 is classified as a medium severity vulnerability due to its impact on ticket status and resolution alteration without proper permissions.
How do I fix CVE-2010-5108?
To fix CVE-2010-5108, update Trac to a version that includes a patch for this vulnerability.
Who is affected by CVE-2010-5108?
CVE-2010-5108 affects users of Trac version 0.11.6 and relevant Debian packages that depend on this version.
What are the consequences of CVE-2010-5108 exploitation?
Exploitation of CVE-2010-5108 allows an attacker to unauthorizedly modify ticket statuses and resolutions, potentially leading to data integrity issues.
Is CVE-2010-5108 still exploitable in newer versions?
CVE-2010-5108 is only exploitable in Trac version 0.11.6 and not in newer, patched versions.