Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history by leveraging access to a privileged account.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html | mailing list patch |
http://secunia.com/advisories/49259 | third party advisory |
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html | mailing list patch |
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/53660 | vdb entry |