CVE Vulnerabilities

CVE-2011-1007

Published: Feb 28, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.

Affected Software

Name Vendor Start Version End Version
Rt Bestpractical * 3.8.9 (including)
Rt Bestpractical 1.0.0 (including) 1.0.0 (including)
Rt Bestpractical 1.0.1 (including) 1.0.1 (including)
Rt Bestpractical 1.0.2 (including) 1.0.2 (including)
Rt Bestpractical 1.0.3 (including) 1.0.3 (including)
Rt Bestpractical 1.0.4 (including) 1.0.4 (including)
Rt Bestpractical 1.0.5 (including) 1.0.5 (including)
Rt Bestpractical 1.0.6 (including) 1.0.6 (including)
Rt Bestpractical 1.0.7 (including) 1.0.7 (including)
Rt Bestpractical 2.0.0 (including) 2.0.0 (including)
Rt Bestpractical 2.0.1 (including) 2.0.1 (including)
Rt Bestpractical 2.0.2 (including) 2.0.2 (including)
Rt Bestpractical 2.0.3 (including) 2.0.3 (including)
Rt Bestpractical 2.0.4 (including) 2.0.4 (including)
Rt Bestpractical 2.0.5 (including) 2.0.5 (including)
Rt Bestpractical 2.0.5.1 (including) 2.0.5.1 (including)
Rt Bestpractical 2.0.5.3 (including) 2.0.5.3 (including)
Rt Bestpractical 2.0.6 (including) 2.0.6 (including)
Rt Bestpractical 2.0.7 (including) 2.0.7 (including)
Rt Bestpractical 2.0.8 (including) 2.0.8 (including)
Rt Bestpractical 2.0.8.2 (including) 2.0.8.2 (including)
Rt Bestpractical 2.0.9 (including) 2.0.9 (including)
Rt Bestpractical 2.0.11 (including) 2.0.11 (including)
Rt Bestpractical 2.0.12 (including) 2.0.12 (including)
Rt Bestpractical 2.0.13 (including) 2.0.13 (including)
Rt Bestpractical 2.0.14 (including) 2.0.14 (including)
Rt Bestpractical 2.0.15 (including) 2.0.15 (including)
Rt Bestpractical 3.0.0 (including) 3.0.0 (including)
Rt Bestpractical 3.0.1 (including) 3.0.1 (including)
Rt Bestpractical 3.0.2 (including) 3.0.2 (including)
Rt Bestpractical 3.0.3 (including) 3.0.3 (including)
Rt Bestpractical 3.0.4 (including) 3.0.4 (including)
Rt Bestpractical 3.0.5 (including) 3.0.5 (including)
Rt Bestpractical 3.0.6 (including) 3.0.6 (including)
Rt Bestpractical 3.0.7 (including) 3.0.7 (including)
Rt Bestpractical 3.0.7.1 (including) 3.0.7.1 (including)
Rt Bestpractical 3.0.8 (including) 3.0.8 (including)
Rt Bestpractical 3.0.9 (including) 3.0.9 (including)
Rt Bestpractical 3.0.10 (including) 3.0.10 (including)
Rt Bestpractical 3.0.11 (including) 3.0.11 (including)
Rt Bestpractical 3.0.12 (including) 3.0.12 (including)
Rt Bestpractical 3.2.0 (including) 3.2.0 (including)
Rt Bestpractical 3.2.1 (including) 3.2.1 (including)
Rt Bestpractical 3.2.2 (including) 3.2.2 (including)
Rt Bestpractical 3.2.3 (including) 3.2.3 (including)
Rt Bestpractical 3.4.0 (including) 3.4.0 (including)
Rt Bestpractical 3.4.1 (including) 3.4.1 (including)
Rt Bestpractical 3.4.2 (including) 3.4.2 (including)
Rt Bestpractical 3.4.3 (including) 3.4.3 (including)
Rt Bestpractical 3.4.4 (including) 3.4.4 (including)
Rt Bestpractical 3.4.5 (including) 3.4.5 (including)
Rt Bestpractical 3.4.6 (including) 3.4.6 (including)
Rt Bestpractical 3.6.0 (including) 3.6.0 (including)
Rt Bestpractical 3.6.1 (including) 3.6.1 (including)
Rt Bestpractical 3.6.2 (including) 3.6.2 (including)
Rt Bestpractical 3.6.3 (including) 3.6.3 (including)
Rt Bestpractical 3.6.4 (including) 3.6.4 (including)
Rt Bestpractical 3.6.5 (including) 3.6.5 (including)
Rt Bestpractical 3.6.6 (including) 3.6.6 (including)
Rt Bestpractical 3.6.7 (including) 3.6.7 (including)
Rt Bestpractical 3.6.8 (including) 3.6.8 (including)
Rt Bestpractical 3.6.9 (including) 3.6.9 (including)
Rt Bestpractical 3.8.0 (including) 3.8.0 (including)
Rt Bestpractical 3.8.1 (including) 3.8.1 (including)
Rt Bestpractical 3.8.2 (including) 3.8.2 (including)
Rt Bestpractical 3.8.3 (including) 3.8.3 (including)
Rt Bestpractical 3.8.4 (including) 3.8.4 (including)
Rt Bestpractical 3.8.5 (including) 3.8.5 (including)
Rt Bestpractical 3.8.6 (including) 3.8.6 (including)
Rt Bestpractical 3.8.6-rc1 (including) 3.8.6-rc1 (including)
Rt Bestpractical 3.8.7-rc1 (including) 3.8.7-rc1 (including)
Rt Bestpractical 3.8.8-rc2 (including) 3.8.8-rc2 (including)
Rt Bestpractical 3.8.8-rc3 (including) 3.8.8-rc3 (including)
Rt Bestpractical 3.8.8-rc4 (including) 3.8.8-rc4 (including)
Rt Bestpractical 3.8.9-rc1 (including) 3.8.9-rc1 (including)
Rt Bestpractical 3.8.9-rc2 (including) 3.8.9-rc2 (including)
Request-tracker3.6 Ubuntu hardy *
Request-tracker3.6 Ubuntu karmic *
Request-tracker3.8 Ubuntu karmic *
Request-tracker3.8 Ubuntu lucid *
Request-tracker3.8 Ubuntu maverick *
Request-tracker3.8 Ubuntu natty *
Request-tracker3.8 Ubuntu upstream *

References