Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44231

Опубликовано: 20 июл. 2026
Источник: debian

Описание

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
request-tracker5fixed5.0.10+dfsg-1package
request-tracker4removedpackage

Примечания

  • https://github.com/bestpractical/rt/releases/tag/rt-5.0.10

  • AuthToken fixes:

  • https://github.com/bestpractical/rt/commit/5e35133b90303c7517b82de7c57cdb891ee61400

  • https://github.com/bestpractical/rt/commit/b2ebecec307fb7a3ae1cf17b8728fae4f3457d7e

  • https://github.com/bestpractical/rt/commit/d4c1f75941aeb54e39be62e5811045aa7a5cb29d

  • https://github.com/bestpractical/rt/commit/79b2cae3757fc1714a392f198c3252358a251ef5

  • https://github.com/bestpractical/rt/commit/ec1235aaf1ce4e3b4025d9ba9fb6dddd3fd61dd2

  • Disable RSS/iCal feeds:

  • https://github.com/bestpractical/rt/commit/e045dfe919aac20b76ca6d6fe026a5471d6569b5

Связанные уязвимости

CVSS3: 9.1
ubuntu
25 дней назад

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.

CVSS3: 9.1
nvd
25 дней назад

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.