CVE-2012-4733

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bestpractical:rt:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc4:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc5:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc6:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc7:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc8:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.10:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.11:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.12:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-08-23 16:55

Updated : 2024-02-28 12:00


NVD link : CVE-2012-4733

Mitre link : CVE-2012-4733

CVE.ORG link : CVE-2012-4733


JSON object : View

Products Affected

bestpractical

  • rt
CWE
CWE-255

Credentials Management Errors