oss-sec mailing list archives

Re: CVE request: MantisBT before 1.2.13 "Change Status To" feature allows unauthorised workflow changes


From: Kurt Seifried <kseifried () redhat com>
Date: Sat, 02 Mar 2013 20:42:43 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 03/01/2013 11:33 AM, Salvatore Bonaccorso wrote:
Hi Kurt

Noticed that the following CVE request did not got a CVE. Would it
be possible to assign a CVE to this?

Yeah odd, I assigned one and then moved the other one to my archive,
not sure why.

On Sat, Jan 19, 2013 at 11:35:06AM +1100, David Hicks wrote:
Hello again list,

Damien Regad (MantisBT developer) discovered and fixed[1] an
access control/permissions bug in MantisBT that exists in
MantisBT version 1.2.12 and prior.

A MantisBT user with "Reporter" permissions (enabling them to 
report/create new issues) can modify the workflow status of any
issue to "New" even if they do not have the necessary permission
to make this change.

Details of the bug, including steps to reproduce and patches are 
available at [1].

References: [1] http://www.mantisbt.org/bugs/view.php?id=15258

As per previous e-mails to this list within the past 24 hours,
MantisBT 1.2.13 is expected to be released early next week.

Can a CVE ID please be assigned to this issue?

ccc


With thanks, David Hicks MantisBT Developer #mantisbt
irc.freenode.net http://www.mantisbt.org/bugs/

Regards, Salvatore



- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)

iQIcBAEBAgAGBQJRMsazAAoJEBYNRVNeJnmTY/AP/1R6Vt4ATt0WGTjlq3L1Expe
yXEdYDCTn5+QL7uXIzM72vEsX00HKIHBIKpga1J/PGCOC7s9cuypWwPKsByENIL4
zUW7fYq+9GQ3GKhhLaAXEKInSzevrhTq3RMV6cIFWsI8oKcT/hvxJu/sPP5LH+NS
rz08+nt5rNuYvRQULZiqSeHdwy8kOsrIYEV0+msqnj92kfPdmIOpWWe/xsQKbNeb
hB2yYvDKnmxkuigkwBsEdeGbTmDah/eiFr3gDlLHgpYKSQRGppSf7rtVhUeMvCT9
31j3+uqbSssALc3k3uOzSD7ytzUzladgrMVnhdSGs0JBFDvD3RMD48TEL9DT/zKm
E65/4lwjl9sbGpdsD2I0/WRKkzuS+yOcefbXszZekR6dRQ/RLypb1/86XJtoPQGu
2rFrj7/5XzkmXVlD68vOHDOcP3qciKgddRCmYkLbgYqdt2KJBfNflVj4tEuvlUFD
+JZvEDJF74Guw2L9ag3Z1kJYzB/aqXLpS+5cnWe5J8y4oTSWFRrH1SdhInI0FUyX
dJzhr+OonElp8UZnXmU/5TZ5pffzvw1qQvYA4DTP5BpFxUDrA2LqTzFhSQmE/Jcp
6ffi6tH5SJJT7sY2WTjoTJDSRjnLPyTtUc+CdXdfrup+LGF4nr8DXzSNav8k+3BU
ocWlaK1JT+9/gK2pPsX/
=P2vN
-----END PGP SIGNATURE-----


Current thread: