All versions of RT from 3.4.6 to 3.8.4 are vulnerable to an escaping bug in the display of Custom Fields that could allow injection of javascript into the RT UI. rt 3.6.9 fixes this issue.
This update has been pushed to testing
This update has been submitted for stable
This update has been pushed to stable
Please login to add feedback.
Confirm request to re-trigger tests.
This update has been pushed to testing
This update has been submitted for stable
This update has been pushed to stable