CVE Vulnerabilities

CVE-2020-29603

Insecure Storage of Sensitive Information

Published: Jan 29, 2021 | Modified: Jan 30, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects names via the manage_proj_edit_page.php project_id parameter, without having access to them.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Mantisbt Mantisbt * 2.24.4 (excluding)

References