CVE-2026-44229
描述
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
如何修補 CVE-2026-44229
要修補 CVE-2026-44229,請將受影響套件升級到下列已修補版本。
- Debian/request-tracker4—未列出修補版本
- Debian/request-tracker5—升級至 5.0.3+dfsg-3~deb12u6 或更新版本
CVE-2026-44229 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-44229 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(2)
- from 0
- from 0, < 5.0.3+dfsg-3~deb12u6