CVE-2004-2666: Medium severity Mantis Mantis vulnerability
Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of viewhistorythreshold, which allows remote attackers to obtain sensitive information (private bug details) by visiting a bug's web page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2666?
CVE-2004-2666 has a medium severity rating as it allows remote attackers to access private bug details.
How do I fix CVE-2004-2666?
To fix CVE-2004-2666, you should upgrade to Mantis versions after 20041016 which contain the necessary security patches.
What types of data are exposed by CVE-2004-2666?
CVE-2004-2666 exposes sensitive information including private bug details stored in the Mantis bug tracking system.
Which versions of Mantis are affected by CVE-2004-2666?
CVE-2004-2666 affects Mantis versions 0.10.2 and earlier, including various other versions in the 0.10.x, 0.14.x, and 0.19.x series.
How can attackers exploit CVE-2004-2666?
Attackers can exploit CVE-2004-2666 by simply visiting the web page of a bug report to view its complete issue history regardless of user permissions.