CVE-2013-3373
EPSS 0.48%Published: 8/23/2013Modified: 4/28/2026
Description
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.
Affected packages (1)
- Debian/request-tracker4from 0, < 4.0.12-2