First published: Mon Oct 18 2021(Updated: )
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bestpractical Request Tracker | >=4.2.0<4.2.17 | |
Bestpractical Request Tracker | >=4.4.0<4.4.5 | |
Bestpractical Request Tracker | >=5.0.0<5.0.2 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =9.0 | |
ubuntu/request-tracker5 | <5.0.2 | 5.0.2 |
ubuntu/request-tracker4 | <4.4.2-2ubuntu0.1~ | 4.4.2-2ubuntu0.1~ |
ubuntu/request-tracker4 | <4.4.3-2+ | 4.4.3-2+ |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.22.04.1 | 4.4.4+dfsg-2ubuntu1.22.04.1 |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.23.04.1 | 4.4.4+dfsg-2ubuntu1.23.04.1 |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.23.10.1 | 4.4.4+dfsg-2ubuntu1.23.10.1 |
debian/request-tracker4 | 4.4.3-2+deb10u2 4.4.3-2+deb10u3 4.4.4+dfsg-2+deb11u2 4.4.4+dfsg-2+deb11u3 4.4.6+dfsg-1.1+deb12u1 4.4.7+dfsg-1 | |
debian/request-tracker5 | 5.0.3+dfsg-3~deb12u2 5.0.5+dfsg-2 |
https://github.com/bestpractical/rt/commit/d16f8cf13c2af517ee55a85e7b91a0267477189f (rt-4.4.5)
https://github.com/bestpractical/rt/commit/d16f8cf13c2af517ee55a85e7b91a0267477189f (rt-4.2.17)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.