MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate severity
GitHub Reviewed
Published
May 12, 2024
in
mantisbt/mantisbt
•
Updated May 14, 2024
Description
Published to the GitHub Advisory Database
May 13, 2024
Reviewed
May 13, 2024
Published by the National Vulnerability Database
May 14, 2024
Last updated
May 14, 2024
If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip.
Impact
Disclosure of the following information:
Patches
See PR mantisbt/mantisbt#2000
Workarounds
None
References
https://mantisbt.org/bugs/view.php?id=34434
References