CVE-2017-5944
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- bestpractical/request tracker
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3882Third Party Advisory
- http://www.securityfocus.com/bid/99381Third Party Advisory, VDB Entry
- https://forum.bestpractical.com/t/security-vulnerabilities-in-rt-2017-06-15/32016Vendor Advisory
- http://www.debian.org/security/2017/dsa-3882Third Party Advisory
- http://www.securityfocus.com/bid/99381Third Party Advisory, VDB Entry
- https://forum.bestpractical.com/t/security-vulnerabilities-in-rt-2017-06-15/32016Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.