CVE-2020-35849: High severity centos libreport-plugin-mantisbt vulnerability
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bugrevisionviewpage.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potentially confidential information via the bugnoteid parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35849?
CVE-2020-35849 is a vulnerability in MantisBT before version 2.24.4 that allows unprivileged attackers to view the Summary field of private issues and bugnotes revisions.
How severe is CVE-2020-35849?
CVE-2020-35849 has a severity rating of high (7.5).
How does CVE-2020-35849 impact MantisBT?
CVE-2020-35849 allows unprivileged attackers to gain access to potentially confidential information by viewing the Summary field of private issues and bugnotes revisions in MantisBT.
What is the affected software by CVE-2020-35849?
The affected software is MantisBT versions up to and exclusive of 2.24.4.
How can I fix CVE-2020-35849?
To fix CVE-2020-35849, it is recommended to upgrade MantisBT to version 2.24.4 or later.