https://bugzilla.redhat.com/show_bug.cgi?id=2503058

            Bug ID: 2503058
           Summary: CVE-2026-44229 rt: cross-site scripting via
                    inline-served uploaded content [fedora-all]
           Product: Fedora
           Version: rawhide
            Status: NEW
        Whiteboard: {"flaws": ["ad50fb7a-0d96-4ec3-95a6-4b35c3cd6cf5"]}
         Component: rt
          Keywords: Security, SecurityTracking
          Severity: medium
          Priority: medium
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
                CC: [email protected], [email protected],
                    [email protected],
                    [email protected]
            Blocks: 2503002 (CVE-2026-44229)
  Target Milestone: ---
    Classification: Fedora



Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.

RT is an open source, enterprise-grade issue and ticket tracking system.
Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a
Cross-Site Scripting (XSS) vulnerability where uploaded content is served
inline rather than as an attachment. An authenticated user who can upload
content can include JavaScript in the upload that will execute in the browser
session of any RT user who later views or downloads it. This issue has been
fixed in versions 5.0.10 and 6.0.3.



Referenced Bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=2503002
[Bug 2503002] CVE-2026-44229 rt: cross-site scripting via inline-served
uploaded content
-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2503058

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202503058%23c0

-- 
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to