Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html | vendor advisory mailing list |
http://www.osvdb.org/93611 | vdb entry |
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.html | patch mailing list |
http://secunia.com/advisories/53522 | third party advisory vendor advisory |