CVE-2014-9759: Infoleak
Published Apr 11, 2016
·Updated
Incomplete blacklist vulnerability in the configisprivate function in configapi.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request.
Affected Software
1 affected component
MantisBT mantisbt=1.3.0-rc1
Remediation
Patch Available
Patch Available
Event History
Apr 11, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9759?
CVE-2014-9759 is considered a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2014-9759?
To fix CVE-2014-9759, upgrade MantisBT to version 1.3.0 or later.
3
What type of vulnerability is CVE-2014-9759?
CVE-2014-9759 is an incomplete blacklist vulnerability affecting the config_is_private function.
4
What information can be exposed by CVE-2014-9759?
CVE-2014-9759 allows remote attackers to obtain sensitive master salt configuration information.
5
In which versions of MantisBT does CVE-2014-9759 exist?
CVE-2014-9759 affects MantisBT version 1.3.x before 1.3.0.