MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip. This can result in disclosure of the existence of the note, the note author name, the note creation timestamp, and the issue id the note belongs to. Version 2.26.2 contains a patch for the issue. No known workarounds are available.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1549 MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip. This can result in disclosure of the existence of the note, the note author name, the note creation timestamp, and the issue id the note belongs to. Version 2.26.2 contains a patch for the issue. No known workarounds are available.
Github GHSA Github GHSA GHSA-99jc-wqmr-ff2q MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mantisbt
Mantisbt mantisbt
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
Vendors & Products Mantisbt
Mantisbt mantisbt

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:42:59.815Z

Reserved: 2024-04-30T06:56:33.384Z

Link: CVE-2024-34080

cve-icon Vulnrichment

Updated: 2024-08-02T02:42:59.815Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T15:38:29.703

Modified: 2025-01-16T16:44:40.283

Link: CVE-2024-34080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.