oss-sec mailing list archives
Re: CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes
From: Salvatore Bonaccorso <carnil () debian org>
Date: Fri, 1 Mar 2013 19:33:43 +0100
Hi Kurt Noticed that the following CVE request did not got a CVE. Would it be possible to assign a CVE to this? On Sat, Jan 19, 2013 at 11:35:06AM +1100, David Hicks wrote:
Hello again list, Damien Regad (MantisBT developer) discovered and fixed[1] an access control/permissions bug in MantisBT that exists in MantisBT version 1.2.12 and prior. A MantisBT user with "Reporter" permissions (enabling them to report/create new issues) can modify the workflow status of any issue to "New" even if they do not have the necessary permission to make this change. Details of the bug, including steps to reproduce and patches are available at [1]. References: [1] http://www.mantisbt.org/bugs/view.php?id=15258 As per previous e-mails to this list within the past 24 hours, MantisBT 1.2.13 is expected to be released early next week. Can a CVE ID please be assigned to this issue? With thanks, David Hicks MantisBT Developer #mantisbt irc.freenode.net http://www.mantisbt.org/bugs/
Regards, Salvatore
Current thread:
- CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes David Hicks (Jan 18)
- Re: CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes Salvatore Bonaccorso (Mar 01)