First published: Thu Oct 31 2019(Updated: )
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | >=1.2.12<1.2.15 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
debian/mantis |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-1930 is medium with a CVSS score of 4.3.
Authenticated users can bypass the workflow restriction and close issues in MantisBT before version 1.2.15.
CVE-2013-1930 affects MantisBT versions 1.2.12 to 1.2.15.
There are no known remedies for CVE-2013-1930 in the Debian Mantis package.
More information about CVE-2013-1930 can be found at the following references: [1](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103438.html), [2](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103459.html), [3](http://www.openwall.com/lists/oss-security/2013/04/06/4)