Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4732
HistoryNov 11, 2012 - 12:00 a.m.

CVE-2012-4732

2012-11-1100:00:00
ubuntu.com
ubuntu.com
9

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

39.2%

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT)
3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions
before 4.0.8, allows remote attackers to hijack the authentication of users
for requests that toggle ticket bookmarks.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchrequest-tracker3.8< 3.8.7-1ubuntu2.3UNKNOWN
ubuntu11.10noarchrequest-tracker3.8< 3.8.10-1ubuntu0.1UNKNOWN
ubuntu12.04noarchrequest-tracker3.8< 3.8.11-1ubuntu0.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

39.2%