Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-1811

Published: 7 November 2019

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

Priority

Medium

Cvss 3 Severity Score

4.3

Score breakdown

Status

Package Release Status
mantis
Launchpad, Ubuntu, Debian
hardy Ignored
(end of life)
lucid Ignored
(end of life)
oneiric Ignored
(end of life)
precise Ignored
(end of life)
quantal Ignored
(end of life)
raring Ignored
(end of life)
saucy Ignored
(end of life)
trusty Does not exist

upstream
Released (1.2.13)
utopic Does not exist

vivid Does not exist

wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist

Patches:
upstream: http://github.com/mantisbt/mantisbt/commit/179bfc016596bf11cb4ac1e3bb6d76acbac30aa0
upstream: http://github.com/mantisbt/mantisbt/commit/53844e3621c390da5143364ddbd4c1850181eb2d
upstream: http://github.com/mantisbt/mantisbt/commit/c88137343b0f6d47613ed7fefc5d1277b901b778
upstream: http://github.com/mantisbt/mantisbt/commit/53282ac6f5c8ebbc5e161d25cf1668243eec2dc4

Severity score breakdown

Parameter Value
Base score 4.3
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact Low
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N