Source: request-tracker5 Version: 5.0.4+dfsg-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org> Control: found -1 5.0.3+dfsg-3~deb12u1 Control: found -1 5.0.3+dfsg-1
Hi Andrew, Dominic, Niko The following vulnerabilities were published for request-tracker5. Filling it in BTS for visiblity there, and for tracking status in the various suites. CVE-2023-41259[0]: | RT is vulnerable to accepting unvalidated RT email headers in | incoming email and the mail-gateway REST interface. This vulnerability | is assigned CVE-2023-41259. CVE-2023-41260[1]: | RT is vulnerable to information leakage via response messages returned | from requests sent via the mail-gateway REST interface. This vulnerability | is assigned CVE-2023-41260. CVE-2023-45024[2]: | RT 5.0 is vulnerable to information leakage via transaction searches made by | authenticated users in the transaction query builder. This vulnerability is | assigned CVE-2023-45024. Thanks to edk and bakerst of Libera Chat for reporting | this finding. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-41259 https://www.cve.org/CVERecord?id=CVE-2023-41259 [1] https://security-tracker.debian.org/tracker/CVE-2023-41260 https://www.cve.org/CVERecord?id=CVE-2023-41260 [2] https://security-tracker.debian.org/tracker/CVE-2023-45024 https://www.cve.org/CVERecord?id=CVE-2023-45024 [3] https://github.com/bestpractical/rt/releases/tag/rt-5.0.5 Regards, Salvatore