First published: Mon Feb 10 2014(Updated: )
SQL injection issues were discovered in MantisBT, an open source issue tracker. <a href="https://access.redhat.com/security/cve/CVE-2014-1608">CVE-2014-1608</a> patch: <a href="https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102">https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102</a> <a href="https://access.redhat.com/security/cve/CVE-2014-1609">CVE-2014-1609</a> patch: <a href="https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f">https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f</a> It was reported that versions 1.1.0a4 to 1.2.15 are affected. References: <a href="http://www.ocert.org/advisories/ocert-2014-001.html">http://www.ocert.org/advisories/ocert-2014-001.html</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mantisbt Mantisbt | <=1.2.15 | |
Mantisbt Mantisbt | =1.2.0 | |
Mantisbt Mantisbt | =1.2.0-alpha1 | |
Mantisbt Mantisbt | =1.2.0-alpha2 | |
Mantisbt Mantisbt | =1.2.0-alpha3 | |
Mantisbt Mantisbt | =1.2.0-rc1 | |
Mantisbt Mantisbt | =1.2.0-rc2 | |
Mantisbt Mantisbt | =1.2.1 | |
Mantisbt Mantisbt | =1.2.2 | |
Mantisbt Mantisbt | =1.2.3 | |
Mantisbt Mantisbt | =1.2.4 | |
Mantisbt Mantisbt | =1.2.5 | |
Mantisbt Mantisbt | =1.2.6 | |
Mantisbt Mantisbt | =1.2.7 | |
Mantisbt Mantisbt | =1.2.8 | |
Mantisbt Mantisbt | =1.2.9 | |
Mantisbt Mantisbt | =1.2.10 | |
Mantisbt Mantisbt | =1.2.11 | |
Mantisbt Mantisbt | =1.2.13 | |
Mantisbt Mantisbt | =1.2.14 | |
Debian Debian Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.