CVE-2020-29603: Medium severity centos libreport-plugin-mantisbt vulnerability
Published Jan 29, 2021
·Updated
In manageprojeditpage.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manageprojeditpage.php projectid parameter, without having access to them.
Affected Software
5 affected componentsFixes available
MantisBT mantisbt<2.24.4
Microsoft Windows
composer/mantisbt/mantisbt<2.24.4
2.24.4
All of the following
MantisBT mantisbt<2.24.4
Microsoft Windows
Remediation
Patch Available
Patch Available
Event History
Jan 29, 2021
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
Description
May 24, 2022
Advisory Published
via GitHub·05:40 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-29603.
2
What is the severity of CVE-2020-29603?
The severity of CVE-2020-29603 is medium with a CVSS score of 4.3.
3
What is the affected software?
The affected software is MantisBT before version 2.24.4.
4
How can an unprivileged logged-in user exploit CVE-2020-29603?
An unprivileged logged-in user can retrieve Private Projects' names via the 'manage_proj_edit_page.php' project_id parameter without having access to them.
5
Is Microsoft Windows affected by CVE-2020-29603?
No, Microsoft Windows is not affected by CVE-2020-29603.