VDB
Sign up
MEDIUM

GHSA-rmp5-5jj7-gmvf

MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue

Quick fix

GHSA-rmp5-5jj7-gmvf — mantisbt/mantisbt: upgrade to the fixed version with the command below.

composer require mantisbt/mantisbt:^2.28.2

Details

MantisBT permits a user to list and download their own attachments from an Issue created by another user, even after that Issue becomes private and direct access to it is denied.

### Impact The loss of confidentiality caused by this vulnerability is minimal, considering that only the attachments that were previously uploaded by the user themselves remains accessible.

### Patches - de7bdeec36de066235e38a77bf056917d951c84d

### Workarounds None.

### Credits

Thanks to Vishal Shukla for discovering and responsibly reporting the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mantisbt/mantisbt
Introduced in: 0Fixed in: 2.28.2
Fixcomposer require mantisbt/mantisbt:^2.28.2

References