Back

MEDIUM

An issue was discovered in MantisBT before 2.24.4

Published Jan 29, 2021

Description

An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private view status, or belonging to a private Project) via the bug_arr[] parameter. This provides full access to potentially confidential information.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 29, 2021
Updated Aug 4, 2024
Reserved Dec 7, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Jan 29, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-21965 GHSA-F38C-WXP6-8XJV