CVE-2013-3374: Medium severity best practical solutions request tracker vulnerability
Unspecified vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13, when using the Apache::Session::File session store, allows remote attackers to obtain sensitive information (user preferences and caches) via unknown vectors, related to a "limited session re-use."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3374?
CVE-2013-3374 has a moderate severity level due to its impact on user privacy and data security.
How do I fix CVE-2013-3374?
To fix CVE-2013-3374, upgrade to Request Tracker version 3.8.17 or 4.0.13 or later.
What types of information can be exposed in CVE-2013-3374?
CVE-2013-3374 allows remote attackers to potentially access sensitive user information, such as preferences and caches.
Which versions of Request Tracker are affected by CVE-2013-3374?
CVE-2013-3374 affects Request Tracker versions 3.8.x before 3.8.17 and 4.0.x before 4.0.13.
Can CVE-2013-3374 be exploited remotely?
Yes, CVE-2013-3374 can be exploited by remote attackers, making it a significant risk.