Best Practical Request Tracker up to 4.2.16/4.4.4/5.0.1 Auth.pm timing discrepancy

A vulnerability was found in Best Practical Request Tracker up to 4.2.16/4.4.4/5.0.1 (Ticket Tracking Software). It has been declared as problematic. Affected by this vulnerability is an unknown code block in the library lib/RT/REST2/Middleware/Auth.pm. Upgrading to version 4.2.17, 4.4.5 or 5.0.2 eliminates this vulnerability. The upgrade is hosted for download at docs.bestpractical.com. Applying the patch 70749bb66cb13dd70bd53340c371038a5f3ca57c is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-49592 : MCAFEE TRIAL INSTALLER 16.0.53 ACCESS CONTROL

CVE-2024-49592 : MCAFEE TRIAL INSTALLER 16.0.53 ACCESS CONTROL

Description McAfee Trial Installer 16.0.53 has Incorrect Access Control that leads to Local Escalation of Privileges. References https://www.mcafee.com/support/s/article/000002516?language=en_US For More

CVE-2024-10934 : OPENBSD UP TO 7.4 ERRATA 020/7.5 ERRATA 007 NFS CLIENT/NFS SERVER DOUBLE FREE

CVE-2024-10934 : OPENBSD UP TO 7.4 ERRATA 020/7.5 ERRATA 007 NFS CLIENT/NFS SERVER DOUBLE FREE

Description In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS

CVE-2024-40638 : GLPI UP TO 10.0.16 SQL INJECTION

CVE-2024-40638 : GLPI UP TO 10.0.16 SQL INJECTION

Description GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities.