Back

MEDIUM

Information exposure vulnerability in Request Tracker (RT)

Published Apr 4, 2024

Description

Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.

Affected products

Remediation

Vendor solution

Vulnerability fixed by applying the following patches: https://github.com/bestpractical/rt/commit/ea07e767eaef5b202e8883051616d09806b8b48a.patch and https://github.com/bestpractical/rt/commit/468f86bd3e82c3b5b5ef7087d416a7509d4b1abe.patch . In future versions of RT, this solution will be included as a configurable option of the tool.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Apr 4, 2024
Updated Nov 3, 2025
Reserved Apr 3, 2024
CISA Vulnrichment
Updated Apr 4, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a