First published: Sun Nov 11 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers to hijack the authentication of users for requests that toggle ticket bookmarks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bestpractical Rt | =3.8.12 | |
Bestpractical Rt | =3.8.13 | |
Bestpractical Rt | =3.8.13-rc1 | |
Bestpractical Rt | =3.8.13-rc2 | |
Bestpractical Rt | =3.8.14 | |
Bestpractical Rt | =3.8.14-rc1 | |
Bestpractical Rt | =4.0.6 | |
Bestpractical Rt | =4.0.7-rc1 | |
Bestpractical Rt | =4.0.8-rc1 | |
Bestpractical Rt | =4.0.8-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.