CVE-2011-1685

Publication date 22 April 2011

Last updated 24 July 2024


Ubuntu priority

Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authenticated users to execute arbitrary code via unspecified vectors, as demonstrated by a cross-site request forgery (CSRF) attack.

Status

Package Ubuntu Release Status
request-tracker3.8 11.10 oneiric
Not affected
11.04 natty
Fixed 3.8.10-1
10.10 maverick
Fixed 3.8.8-4ubuntu0.1
10.04 LTS lucid
Fixed 3.8.7-1ubuntu2.2
9.10 karmic Ignored end of life
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release