CVE-2012-4733
Publication date 23 August 2013
Last updated 24 July 2024
Ubuntu priority
Description
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| request-tracker4 | ||
| request-tracker3.8 | ||