Search CVE reports


Toggle filters

11 – 20 of 63 results


CVE-2023-41260

Medium priority

Some fixes available 6 of 9

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

2 affected packages

request-tracker4, request-tracker5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Not affected Fixed Fixed Fixed
request-tracker5 Not affected Fixed Not in release Not in release
Show less packages

CVE-2023-41259

Medium priority

Some fixes available 6 of 9

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

2 affected packages

request-tracker4, request-tracker5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Not affected Fixed Fixed Fixed
request-tracker5 Not affected Fixed Not in release Ignored
Show less packages

CVE-2023-28439

Medium priority

Some fixes available 4 of 36

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after...

4 affected packages

ldap-account-manager, request-tracker4, ckeditor, ckeditor3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Fixed Fixed Fixed
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-22457

Medium priority
Needs evaluation

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-48110

Medium priority
Ignored

CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation...

4 affected packages

ldap-account-manager, request-tracker4, ckeditor3, ckeditor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldap-account-manager Not affected Not affected Not affected Not affected
request-tracker4 Not affected Not affected Not affected Not affected
ckeditor3 Not affected Not affected Not affected Not affected
ckeditor Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-31175

Medium priority
Needs evaluation

CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript...

4 affected packages

request-tracker4, ckeditor, ckeditor3, ldap-account-manager

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-25802

Medium priority

Some fixes available 6 of 14

Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.

2 affected packages

request-tracker5, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker5 Not affected Fixed Not in release Not in release
request-tracker4 Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-24729

Low priority
Needs evaluation

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator...

4 affected packages

request-tracker4, ckeditor, ckeditor3, ldap-account-manager

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not affected Not affected Not affected Not affected
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24728

Medium priority

Some fixes available 4 of 40

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Fixed Fixed Fixed
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-41165

Medium priority
Needs evaluation

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject...

4 affected packages

ckeditor, ckeditor3, ldap-account-manager, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Needs evaluation Needs evaluation Needs evaluation
ckeditor3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages