CVE-2012-4732
EPSS 0.12%
Description
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers to hijack the authentication of users for requests that toggle ticket bookmarks.
How to fix CVE-2012-4732
To remediate CVE-2012-4732, upgrade the affected package to a fixed version below.
- Debian/request-tracker4—upgrade to 4.0.7-2 or later
Is CVE-2012-4732 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.0.7-2