MEDIUM
An issue was discovered in MantisBT before 2.24.4
Published Jan 29, 2021
6.5
MEDIUMCVSS 3.1
EPSS 1.11%
Description
An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private view status, or belonging to a private Project) via the bug_arr[] parameter. This provides full access to potentially confidential information.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21965 Advisory
- https://github.com/advisories/GHSA-f38c-wxp6-8xjv Advisory
- https://github.com/mantisbt/mantisbt/commit/b2da7352b0ad31fa5f925eaacb4b2b96a6cec8e8
- https://mantisbt.org/bugs/view.php?id=27357 x_refsource_MISCExploitPatchVendor Advisory
- https://mantisbt.org/bugs/view.php?id=27728 x_refsource_MISCExploitPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-29604
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21965 | Advisory | |
| https://github.com/advisories/GHSA-f38c-wxp6-8xjv | Advisory | |
| https://github.com/mantisbt/mantisbt/commit/b2da7352b0ad31fa5f925eaacb4b2b96a6cec8e8 | ||
| https://mantisbt.org/bugs/view.php?id=27357 | x_refsource_MISCExploitPatchVendor Advisory | |
| https://mantisbt.org/bugs/view.php?id=27728 | x_refsource_MISCExploitPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-29604 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 29, 2021
Updated Aug 4, 2024
Reserved Dec 7, 2020
Link CVE-2020-29604
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-21965 GHSA-F38C-WXP6-8XJV Assigner mitre
Published Jan 29, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-21965