Mantis Print Reports Limit Reporters Option Bypass Vulnerability
BID:5515
Info
Mantis Print Reports Limit Reporters Option Bypass Vulnerability
| Bugtraq ID: | 5515 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1111 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery of this issue is credited to Jeroen Latour <[email protected]>. |
| Vulnerable: |
Mantis Mantis 0.17.3 Mantis Mantis 0.17.2 Mantis Mantis 0.17.1 Mantis Mantis 0.17 .0 Mantis Mantis 0.16.1 Mantis Mantis 0.16 .0 |
| Not Vulnerable: |
Mantis Mantis 0.17.4 a Mantis Mantis 0.17.4 Mantis Mantis 0.15.12 Mantis Mantis 0.15.11 Mantis Mantis 0.15.10 Mantis Mantis 0.15.9 Mantis Mantis 0.15.8 Mantis Mantis 0.15.7 Mantis Mantis 0.15.6 Mantis Mantis 0.15.5 Mantis Mantis 0.15.4 Mantis Mantis 0.15.3 |
Discussion
Mantis Print Reports Limit Reporters Option Bypass Vulnerability
Mantis is a web-based bug tracking system. It is written in PHP and back-ended by a MySQL database.
Mantis is prone to an issue which may allow malicious users of the bug tracking system to gain unauthorized access to restricted bug summaries. This may be a security concern in organizations that use the software to restrict viewing rights of bugs to some users.
Mantis includes the option limit_reporters, which allows users to view only those bugs which they reported. This functionality is not, however, implemented in the 'print_all_bug_page.php' script, used to format bug results for printing. Valid users may be able to view summary information for all bugs, not just those they have reported.
Mantis is a web-based bug tracking system. It is written in PHP and back-ended by a MySQL database.
Mantis is prone to an issue which may allow malicious users of the bug tracking system to gain unauthorized access to restricted bug summaries. This may be a security concern in organizations that use the software to restrict viewing rights of bugs to some users.
Mantis includes the option limit_reporters, which allows users to view only those bugs which they reported. This functionality is not, however, implemented in the 'print_all_bug_page.php' script, used to format bug results for printing. Valid users may be able to view summary information for all bugs, not just those they have reported.
Exploit / POC
Mantis Print Reports Limit Reporters Option Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Mantis Print Reports Limit Reporters Option Bypass Vulnerability
Solution:
The vendor has included a source code fix:
In print_all_bug_page.php, after the block of assignments from $t_setting_arr, insert the following lines:
# Limit reporters to only see their reported bugs
if (( ON == $g_limit_reporters ) &&
( !access_level_check_greater_or_equal( UPDATER ) )) {
$f_user_id = get_current_user_field( "id" );
}
The vendor has addressed this issue in Mantis 0.17.4 and later:
Mantis Mantis 0.16 .0
Mantis Mantis 0.16.1
Mantis Mantis 0.17 .0
Mantis Mantis 0.17.1
Mantis Mantis 0.17.2
Mantis Mantis 0.17.3
Solution:
The vendor has included a source code fix:
In print_all_bug_page.php, after the block of assignments from $t_setting_arr, insert the following lines:
# Limit reporters to only see their reported bugs
if (( ON == $g_limit_reporters ) &&
( !access_level_check_greater_or_equal( UPDATER ) )) {
$f_user_id = get_current_user_field( "id" );
}
The vendor has addressed this issue in Mantis 0.17.4 and later:
Mantis Mantis 0.16 .0
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.16.1
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17 .0
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.1
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.2
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
Mantis Mantis 0.17.3
-
Mantis Mantis 0.17.4a
http://sourceforge.net/project/showfiles.php?group_id=14963
References
Mantis Print Reports Limit Reporters Option Bypass Vulnerability
References:
References:
- Mantis Homepage (Mantis)