Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-06-04T19:00:00

Updated: 2012-09-29T09:00:00

Reserved: 2011-11-16T00:00:00


Link: CVE-2011-4459

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-06-04T19:55:01.807

Modified: 2012-09-29T03:13:03.407


Link: CVE-2011-4459

JSON object: View

cve-icon Redhat Information

No data.

CWE