Lucene search

K
freebsdFreeBSD83B38A2C-413E-11E5-BFCF-6805CA0B3D42
HistoryAug 12, 2015 - 12:00 a.m.

RT -- two XSS vulnerabilities

2015-08-1200:00:00
vuxml.freebsd.org
24

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

68.5%

Best Practical reports:

RT 4.0.0 and above are vulnerable to a cross-site
scripting (XSS) attack via the user and group rights
management pages. This vulnerability is assigned
CVE-2015-5475. It was discovered and reported by Marcin
Kopec at Data Reliance Shared Service Center.
RT 4.2.0 and above are vulnerable to a cross-site
scripting (XSS) attack via the cryptography interface.
This vulnerability could allow an attacker with a
carefully-crafted key to inject JavaScript into RT’s user
interface. Installations which use neither GnuPG nor
S/MIME are unaffected.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchrt42= 4.2.0UNKNOWN
FreeBSDanynoarchrt42< 4.2.12UNKNOWN
FreeBSDanynoarchrt40= 4.0.0UNKNOWN
FreeBSDanynoarchrt40< 4.0.24UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

68.5%