---
title: "CVE-2011-1685\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-1685?format=md
keywords: index, follow
---

# CVE-2011-1685

Publication date 22 April 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through
4.0.0rc7, when the CustomFieldValuesSources (aka external custom field)
option is enabled, allows remote authenticated users to execute arbitrary
code via unspecified vectors, as demonstrated by a cross-site request
forgery (CSRF) attack.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| request-tracker3.8 | 11.10 oneiric | Not affected |
| 11.04 natty | Fixed 3.8.10-1 |
| 10.10 maverick | Fixed 3.8.8-4ubuntu0.1 |
| 10.04 LTS lucid | Fixed 3.8.7-1ubuntu2.2 |
| 9.10 karmic | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1685)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-1685)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-1685)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-1685)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-1685>
