Описание
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| request-tracker5 | fixed | 5.0.10+dfsg-1 | package | |
| request-tracker5 | fixed | 5.0.7+dfsg-4+deb13u3 | trixie | package |
| request-tracker5 | not-affected | bookworm | package |
Примечания
https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
Introduced with: https://github.com/bestpractical/rt/commit/1db06229c5839a158f2365c436d9aa325d6ea459 (rt-5.0.4beta1)
Fixed by: https://github.com/bestpractical/rt/commit/510d8d6c6a260da22830039e362c990a6c029665 (rt-5.0.10)
EPSS
Связанные уязвимости
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
EPSS