Relationship Graph

Relationship Graph
related to related to child of child of duplicate of duplicate of

View Issue Details

IDProjectCategoryView StatusLast Update
0020109mantisbtsecuritypublic2016-04-04 11:07
Reporterdregad Assigned Todregad  
PriorityhighSeveritymajorReproducibilityalways
Status closedResolutionduplicate 
Product Version1.2.19 
Target Version1.3.0-beta.3Fixed in Version1.3.0-beta.3 
Summary0020109: CVE-2015-5059: documentation in private projects can be seen by every user
Description

This is a clone of 0019873 to track the vulnerability in 1.3.x branch

TagsNo tags attached.

Relationships

duplicate of 0019873 closeddregad CVE-2015-5059: documentation in private projects can be seen by every user 

Activities

There are no notes attached to this issue.

Related Changesets

MantisBT: master a4be76d6

2015-06-24 04:52

dregad


Details Diff
Change default threshold to view project doc to VIEWER

Previously it was ANYBODY, which would let any user download files from
any project including private ones, even when they are not part of the
team.

Fixes 0019873
Affected Issues
0019873, 0020109
mod - config_defaults_inc.php Diff File