Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 19 Jan 2013 11:35:06 +1100
From: David Hicks <d@...id.au>
To: oss-security@...ts.openwall.com
Cc: Damien Regad <damien.regad@...ckgroup.com>
Subject: CVE request: MantisBT before 1.2.13 "Change Status To" feature
 allows unauthorised workflow changes

Hello again list,

Damien Regad (MantisBT developer) discovered and fixed[1] an access
control/permissions bug in MantisBT that exists in MantisBT version
1.2.12 and prior.

A MantisBT user with "Reporter" permissions (enabling them to
report/create new issues) can modify the workflow status of any issue to
"New" even if they do not have the necessary permission to make this
change.

Details of the bug, including steps to reproduce and patches are
available at [1].

References:
[1] http://www.mantisbt.org/bugs/view.php?id=15258

As per previous e-mails to this list within the past 24 hours, MantisBT
1.2.13 is expected to be released early next week.

Can a CVE ID please be assigned to this issue?

With thanks,
David Hicks
MantisBT Developer
#mantisbt irc.freenode.net
http://www.mantisbt.org/bugs/

Bcc: mantisbt-dev@...ts.sourceforge.net

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ