CVE Vulnerabilities

CVE-2012-4733

Published: Aug 23, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and custom lifecycle transition permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
RtBestpractical4.0.0 (including)4.0.0 (including)
RtBestpractical4.0.0-rc1 (including)4.0.0-rc1 (including)
RtBestpractical4.0.0-rc2 (including)4.0.0-rc2 (including)
RtBestpractical4.0.0-rc3 (including)4.0.0-rc3 (including)
RtBestpractical4.0.0-rc4 (including)4.0.0-rc4 (including)
RtBestpractical4.0.0-rc5 (including)4.0.0-rc5 (including)
RtBestpractical4.0.0-rc6 (including)4.0.0-rc6 (including)
RtBestpractical4.0.0-rc7 (including)4.0.0-rc7 (including)
RtBestpractical4.0.0-rc8 (including)4.0.0-rc8 (including)
RtBestpractical4.0.1 (including)4.0.1 (including)
RtBestpractical4.0.1-rc1 (including)4.0.1-rc1 (including)
RtBestpractical4.0.1-rc2 (including)4.0.1-rc2 (including)
RtBestpractical4.0.2 (including)4.0.2 (including)
RtBestpractical4.0.2-rc1 (including)4.0.2-rc1 (including)
RtBestpractical4.0.2-rc2 (including)4.0.2-rc2 (including)
RtBestpractical4.0.3 (including)4.0.3 (including)
RtBestpractical4.0.10 (including)4.0.10 (including)
RtBestpractical4.0.11 (including)4.0.11 (including)
RtBestpractical4.0.12 (including)4.0.12 (including)
Request-tracker4Ubuntuprecise*
Request-tracker4Ubuntuquantal*
Request-tracker4Ubunturaring*
Request-tracker4Ubuntuupstream*

References