NA

CVE-2024-3262

Published: 04/04/2024 Updated: 04/04/2024

Vulnerability Summary

Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.

Vendor Advisories

Debian Bug report logs - #1068452 request-tracker4: CVE-2024-3262 Package: src:request-tracker4; Maintainer for src:request-tracker4 is Debian Request Tracker Group <pkg-request-tracker-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 5 Apr 2024 14:45:02 UTC Severity: ...