oss-sec mailing list archives

CVE Request: Information disclosure in MantisBT

From: Damien Regad <dregad () mantisbt org>
Date: Thu, 25 Jun 2015 01:04:32 +0200


Please assign a CVE ID for the following issue.


In MantisBT, the "Project Documentation" feature can be used to attach files to a project.

When this feature is enabled ($g_enable_project_documentation = ON) and the threshold to view these files is left to its default value ($g_view_proj_doc_threshold = ANYBODY), any registered user in the system can download every such attachment, including those which are linked to private projects to which the user does not have access.

This can be achieved by calling the download script directly, and specifying the ID of the file to download, e.g.


Affected versions:
- <= 1.2.19
- <= 1.3.0-beta.2

Fixed in versions:
- 1.2.20 (not yet released)
- 1.3.0-rc1 (not yet released)

See Github [1]

The issue was discovered by Werner Karl and fixed by Damien Regad
(MantisBT Developer).

Further details available in our issue tracker [2]

Best regards,
D. Regad
MantisBT Developer

[1] http://github.com/mantisbt/mantisbt/commit/f39cf525 (1.2.x)
    http://github.com/mantisbt/mantisbt/commit/a4be76d6 (1.3.x)
[2] https://mantisbt.org/bugs/view.php?id=19873

Current thread: