Description
Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers to obtain sensitive information (private bug details) by visiting a bug's web page.
Product(s):
- Mantis 0.10.1
- Mantis 0.10.2
- Mantis 0.10
- Mantis 0.11.1
- Mantis 0.11
- Mantis 0.12
- Mantis 0.13.1
- Mantis 0.13
- Mantis 0.14.1
- Mantis 0.14.2
- Mantis 0.14.3
- Mantis 0.14.4
- Mantis 0.14.5
- Mantis 0.14.6
- Mantis 0.14.7
- Mantis 0.14.8
- Mantis 0.14
- Mantis 0.15.10
- Mantis 0.15.11
- Mantis 0.15.12
- Mantis 0.15.1
- Mantis 0.15.2
- Mantis 0.15.3
- Mantis 0.15.4
- Mantis 0.15.5
- Mantis 0.15.6
- Mantis 0.15.7
- Mantis 0.15.8
- Mantis 0.15.9
- Mantis 0.15
- Mantis 0.16.1
- Mantis 0.16
- Mantis 0.17.1
- Mantis 0.17.2
- Mantis 0.17.3
- Mantis 0.17.4
- Mantis 0.17.4a
- Mantis 0.17.5
- Mantis 0.17
- Mantis 0.18.0 RC1
- Mantis 0.18.0a1
- Mantis 0.18.0a2
- Mantis 0.18.0a3
- Mantis 0.18.0a4
- Mantis 0.18.1
- Mantis 0.18.2
- Mantis 0.18.3
- Mantis 0.18
- Mantis 0.18a1
- Mantis 0.19.0 RC1
- Mantis 0.19.0a1
- Mantis 0.19.0a2
- Mantis 0.19.0a
- Mantis 0.19
- Mantis 0.9.1
- Mantis 0.9
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-2666, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-2666 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.