CVE-2012-4734: CSRF
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to a crafted link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4734?
CVE-2012-4734 has a moderate severity rating due to its potential for exploitation in bypassing CSRF protections.
How do I fix CVE-2012-4734?
To fix CVE-2012-4734, upgrade to Request Tracker version 3.8.15 or later for the 3.8.x series or 4.0.8 or later for the 4.0.x series.
What versions of Request Tracker are affected by CVE-2012-4734?
CVE-2012-4734 affects Request Tracker versions 3.8.0 through 3.8.14 and 4.0.0 through 4.0.7.
What attack is described by CVE-2012-4734?
CVE-2012-4734 describes a "confused deputy" attack that allows an attacker to bypass CSRF warning protections.
Is there a workaround for CVE-2012-4734?
There is no official workaround for CVE-2012-4734; the recommended action is to upgrade to a secure version.