Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in Request Tracker.. ========================================================================== Ubuntu Security Notice USN-7692-1 August 13, 2025 request-tracker5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Request Tracker. Software Description: - request-tracker5: An open source, enterprise-grade issue and ticket tracking system. Details: It was discovered that Request Tracker was susceptible to timing attacks. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2021-38562) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious attachments were supplied. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-25802) It was discovered that Request Tracker would incorrectly redirect users in certain instances. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-25803) Tom Wolters discovered that Request Tracker could leak information when malicious email headers were supplied. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-41259, CVE-2023-41260) It was discovered that Request Tracker could leak information through its transaction search. An attacker with access to the transaction query builder of Request Tracker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-45024) It was discovered that Request Tracker erroneously stored ticket information in a web browser's cache. An attacker with direct access to a system could possibly use this issue to accesssensitive information. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-3262) It was discovered that Request Tracker made use of an obsolete cryptographic algorithm for emails sent with S/MIME encryption. An attacker could possibly use this issue to access sensitive information. (CVE-2025-2545) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious parameters were included in a search URL. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-30087) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious permalinks or assets were provided. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-31500, CVE-2025-31501) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 request-tracker5 5.0.7+dfsg-2ubuntu0.1 rt5-fcgi 5.0.7+dfsg-2ubuntu0.1 rt5-standalone 5.0.7+dfsg-2ubuntu0.1 Ubuntu 24.04 LTS request-tracker5 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro rt5-fcgi 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro rt5-standalone 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS request-tracker5 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro rt5-fcgi 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro rt5-standalone 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro After a standard system update you need to restart Request Tracker to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7692-1 CVE-2021-38562, CVE-2022-25802,CVE-2022-25803, CVE-2023-41259, CVE-2023-41260, CVE-2023-45024, CVE-2024-3262, CVE-2025-2545, CVE-2025-30087, CVE-2025-31500, CVE-2025-31501 Package Information: https://launchpad.net/ubuntu/+source/request-tracker5/5.0.7+dfsg-2ubuntu0.1 . Various vulnerabilities addressed in Request Tracker impact Long Term Support versions of Ubuntu, resulting in possible exposure of confidential information.. Request Tracker, Ubuntu security advisory, denial of service, cross-site scripting, Ubuntu LTS. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4157-1
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5911-1
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5909-1
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5909-1
Several security issues were fixed in Request Tracker.. ========================================================================== Ubuntu Security Notice USN-6529-1 December 04, 2023 request-tracker4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Request Tracker. Software Description: - request-tracker4: An enterprise-grade issue tracking system Details: It was discovered that Request Tracker incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-38562, CVE-2022-25802, CVE-2023-41259, CVE-2023-41260) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: request-tracker4 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-clients 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.23.10.1 Ubuntu 23.04: request-tracker4 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-clients 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.23.04.1 Ubuntu 22.04 LTS: request-tracker4 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-clients 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.22.04.1 Ubuntu 20.04 LTS: request-tracker4 4.4.3-2+deb10u3build0.20.04.1 rt4-apache2 4.4.3-2+deb10u3build0.20.04.1 rt4-clients 4.4.3-2+deb10u3build0.20.04.1 rt4-db-mysql 4.4.3-2+deb10u3build0.20.04.1 rt4-db-postgresql 4.4.3-2+deb10u3build0.20.04.1 rt4-db-sqlite 4.4.3-2+deb10u3build0.20.04.1 rt4-fcgi 4.4.3-2+deb10u3build0.20.04.1 rt4-standalone 4.4.3-2+deb10u3build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): request-tracker4 4.4.2-2ubuntu0.1~esm1 rt4-apache2 4.4.2-2ubuntu0.1~esm1 rt4-clients 4.4.2-2ubuntu0.1~esm1 rt4-db-mysql 4.4.2-2ubuntu0.1~esm1 rt4-db-postgresql 4.4.2-2ubuntu0.1~esm1 rt4-db-sqlite 4.4.2-2ubuntu0.1~esm1 rt4-fcgi 4.4.2-2ubuntu0.1~esm1 rt4-standalone 4.4.2-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6529-1 CVE-2021-38562, CVE-2022-25802, CVE-2023-41259, CVE-2023-41260 Package Information: https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.10.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.04.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.22.04.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.3-2+deb10u3build0.20.04.1 . Ubuntu Security Notice USN-6529-1 December 04, 2023 request-tracker4 vulnerabilities A security issu. security, request, tracker, =============================================. . LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3642-1
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5542-1
Get the latest Linux and open source security news straight to your inbox.