LWN.net Logo

mantis: information disclosure

Package(s):mantis CVE #(s):CVE-2006-6574
Created:January 21, 2008 Updated:January 23, 2008
Description:

From the NVD entry:

Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.

Alerts:
Debian DSA-1467-1 2008-01-19

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds