Bug 1179304 (CVE-2014-9506) - CVE-2014-9506 mantis: information disclosure when sending e-mails about "related" issues
Summary: CVE-2014-9506 mantis: information disclosure when sending e-mails about "rela...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-9506
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-01-06 14:46 UTC by Vasyl Kaigorodov
Modified: 2021-10-20 10:49 UTC (History)
2 users (show)

Fixed In Version: MantisBT 1.2.18
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-20 10:49:28 UTC
Embargoed:


Attachments (Terms of Use)

Description Vasyl Kaigorodov 2015-01-06 14:46:33 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-9506 to
the following vulnerability:

Name: CVE-2014-9506
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9506
Assigned: 20150104
Reference: https://www.mantisbt.org/bugs/view.php?id=9885

MantisBT before 1.2.18 does not properly check permissions when
sending an email that indicates when a monitored issue is related to
another issue, which allows remote authenticated users to obtain
sensitive information about restricted issues.


Note You need to log in before you can comment on or make changes to this bug.