Mantis Unauthorized Project Bug List Viewing Vulnerability
BID:5514
Info
Mantis Unauthorized Project Bug List Viewing Vulnerability
| Bugtraq ID: | 5514 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1112 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery of this issue is credited to Jeroen Latour <[email protected]>. |
| Vulnerable: |
Mantis Mantis 0.17.3 Mantis Mantis 0.17.2 Mantis Mantis 0.17.1 Mantis Mantis 0.17 .0 Mantis Mantis 0.16.1 Mantis Mantis 0.16 .0 Mantis Mantis 0.15.12 Mantis Mantis 0.15.11 Mantis Mantis 0.15.10 Mantis Mantis 0.15.9 Mantis Mantis 0.15.8 Mantis Mantis 0.15.7 Mantis Mantis 0.15.6 Mantis Mantis 0.15.5 Mantis Mantis 0.15.4 Mantis Mantis 0.15.3 |
| Not Vulnerable: |
Mantis Mantis 0.17.4 a Mantis Mantis 0.17.4 |
Discussion
Mantis Unauthorized Project Bug List Viewing Vulnerability
Mantis is prone to an issue which may allow malicious users of the bug tracking system to gain unauthorized access to restricted projects.
Vulnerable versions of Mantis do not adequately check that a user has access to projects. It has been reported that a malicious user may manipulate values in cookie-based authentication credentials to gain unauthorized viewing rights to bugs in other projects. However, exploitation of this issue is limited to gaining a listing of 'Public' bugs in other projects.
This issue was reported in Mantis 0.17.3. Earlier versions are also believed to be affected.
Mantis is prone to an issue which may allow malicious users of the bug tracking system to gain unauthorized access to restricted projects.
Vulnerable versions of Mantis do not adequately check that a user has access to projects. It has been reported that a malicious user may manipulate values in cookie-based authentication credentials to gain unauthorized viewing rights to bugs in other projects. However, exploitation of this issue is limited to gaining a listing of 'Public' bugs in other projects.
This issue was reported in Mantis 0.17.3. Earlier versions are also believed to be affected.
Exploit / POC
Mantis Unauthorized Project Bug List Viewing Vulnerability
This issue may be exploited with a web browser and a text editor.
This issue may be exploited with a web browser and a text editor.
Solution / Fix
Mantis Unauthorized Project Bug List Viewing Vulnerability
Solution:
The vendor has included a source code fix:
Add the following function to core_user_API.php:
# Check to see if the current user has access on the specified project
function check_access_to_project( $p_project_id ) {
$t_project_view_state = get_project_field( $p_project_id,
'view_state' );
# Administrators ALWAYS pass.
if ( get_current_user_field( 'access_level' ) >= ADMINISTRATOR ) {
return;
}
# public project accept all users
if ( PUBLIC == $t_project_view_state ) {
return;
} else {
# private projects require users to be assigned
$t_project_access_level = get_project_access_level( $p_project_id );
# -1 means not assigned, kick them out to the project selection screen
if ( -1 == $t_project_access_level ) {
print_header_redirect( 'login_select_proj_page.php' );
} else { # passed
return;
}
}
}
And in view_all_bug_page.php, replace the following lines:
$t_where_clause .= ')';
}
} else {
$t_where_clause = " WHERE project_id='$g_project_cookie_val'";
}
# end project selection
with the following lines:
$t_where_clause .= ')';
}
} else {
check_access_to_project($g_project_cookie_val);
$t_where_clause = " WHERE project_id='$g_project_cookie_val'";
}
# end project selection
The vendor has addressed this issue in Mantis 0.17.4 and later:
Mantis Mantis 0.15.10
Mantis Mantis 0.15.11
Mantis Mantis 0.15.12
Mantis Mantis 0.15.3
Mantis Mantis 0.15.4
Mantis Mantis 0.15.5
Mantis Mantis 0.15.6
Mantis Mantis 0.15.7
Mantis Mantis 0.15.8
Mantis Mantis 0.15.9
Mantis Mantis 0.16 .0
Mantis Mantis 0.16.1
Mantis Mantis 0.17 .0
Mantis Mantis 0.17.1
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
Solution:
The vendor has included a source code fix:
Add the following function to core_user_API.php:
# Check to see if the current user has access on the specified project
function check_access_to_project( $p_project_id ) {
$t_project_view_state = get_project_field( $p_project_id,
'view_state' );
# Administrators ALWAYS pass.
if ( get_current_user_field( 'access_level' ) >= ADMINISTRATOR ) {
return;
}
# public project accept all users
if ( PUBLIC == $t_project_view_state ) {
return;
} else {
# private projects require users to be assigned
$t_project_access_level = get_project_access_level( $p_project_id );
# -1 means not assigned, kick them out to the project selection screen
if ( -1 == $t_project_access_level ) {
print_header_redirect( 'login_select_proj_page.php' );
} else { # passed
return;
}
}
}
And in view_all_bug_page.php, replace the following lines:
$t_where_clause .= ')';
}
} else {
$t_where_clause = " WHERE project_id='$g_project_cookie_val'";
}
# end project selection
with the following lines:
$t_where_clause .= ')';
}
} else {
check_access_to_project($g_project_cookie_val);
$t_where_clause = " WHERE project_id='$g_project_cookie_val'";
}
# end project selection
The vendor has addressed this issue in Mantis 0.17.4 and later:
Mantis Mantis 0.15.10
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.11
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.12
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.3
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.4
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.5
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.6
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.7
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.8
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.15.9
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.16 .0
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.16.1
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17 .0
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.1
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.2
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.3
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963