The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the context of the logged-in user. This vulnerability affects versions from 5.0.4 through 5.0.8 and from 6.0.0 through 6.0.1.
{
"binaries": [
{
"binary_name": "request-tracker5",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-apache2",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-clients",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-mysql",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-postgresql",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-sqlite",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-doc-html",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-fcgi",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-standalone",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
}
]
}
{
"binaries": [
{
"binary_name": "request-tracker5",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-apache2",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-clients",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-db-mysql",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-db-postgresql",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-db-sqlite",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-doc-html",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-fcgi",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
},
{
"binary_name": "rt5-standalone",
"binary_version": "5.0.5+dfsg-2ubuntu0.1~esm1"
}
]
}
{
"binaries": [
{
"binary_name": "request-tracker5",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-apache2",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-clients",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-db-mysql",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-db-postgresql",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-db-sqlite",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-doc-html",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-fcgi",
"binary_version": "5.0.7+dfsg-4"
},
{
"binary_name": "rt5-standalone",
"binary_version": "5.0.7+dfsg-4"
}
]
}
{
"binaries": [
{
"binary_name": "request-tracker5",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-apache2",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-clients",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-db-mysql",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-db-postgresql",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-db-sqlite",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-doc-html",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-fcgi",
"binary_version": "5.0.7+dfsg-6"
},
{
"binary_name": "rt5-standalone",
"binary_version": "5.0.7+dfsg-6"
}
]
}