CVE-2014-8553: Infoleak
The mciaccountgetarraybyid function in api/soap/mcaccountapi.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive information via a (1) mcprojectgetusers, (2) mcissueget, (3) mcfiltergetissues, or (4) mcprojectgetissues SOAP request.
Other sources
Version 1.2.18 of MantisBT fixes unspecified information disclosure issue [1]. Upstream bug (private) is at [2].
[1]: http://seclists.org/oss-sec/2014/q4/955 [2]: http://www.mantisbt.org/bugs/view.php?id=17243
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8553?
CVE-2014-8553 has a medium severity rating as it allows remote attackers to access sensitive information.
How do I fix CVE-2014-8553?
To fix CVE-2014-8553, upgrade MantisBT to version 1.2.18 or later.
Which versions are affected by CVE-2014-8553?
CVE-2014-8553 affects MantisBT versions prior to 1.2.18.
What type of attack does CVE-2014-8553 facilitate?
CVE-2014-8553 facilitates remote information disclosure attacks.
Are there any mitigations for CVE-2014-8553?
The best mitigation for CVE-2014-8553 is to apply the required software update as soon as possible.