CVE-2024-3262 MEDIUM

CVE-2024-3262: Information exposure vulnerability in Request Tracker (RT)

Vendor Best Practical Solutions
Product Request Tracker
Weakness CWE-200 · Info exposure
Published April 4, 2024
Last update November 3, 2025

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.

Key dates

02Disclosure timeline

April 4, 2024 CVE published
November 3, 2025 Record updated