Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130301183343.GB29447@elende>
Date: Fri, 1 Mar 2013 19:33:43 +0100
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Cc: Damien Regad <damien.regad@...ckgroup.com>
Subject: Re: CVE request: MantisBT before 1.2.13 "Change
 Status To" feature allows unauthorised workflow changes

Hi Kurt

Noticed that the following CVE request did not got a CVE. Would it be
possible to assign a CVE to this?

On Sat, Jan 19, 2013 at 11:35:06AM +1100, David Hicks wrote:
> Hello again list,
> 
> Damien Regad (MantisBT developer) discovered and fixed[1] an access
> control/permissions bug in MantisBT that exists in MantisBT version
> 1.2.12 and prior.
> 
> A MantisBT user with "Reporter" permissions (enabling them to
> report/create new issues) can modify the workflow status of any issue to
> "New" even if they do not have the necessary permission to make this
> change.
> 
> Details of the bug, including steps to reproduce and patches are
> available at [1].
> 
> References:
> [1] http://www.mantisbt.org/bugs/view.php?id=15258
> 
> As per previous e-mails to this list within the past 24 hours, MantisBT
> 1.2.13 is expected to be released early next week.
> 
> Can a CVE ID please be assigned to this issue?
> 
> With thanks,
> David Hicks
> MantisBT Developer
> #mantisbt irc.freenode.net
> http://www.mantisbt.org/bugs/

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.