Описание
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.
Ссылки
- Patch
- Patch
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.27.2 (исключая)
cpe:2.3:a:mantisbt:mantisbt:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 6.5
debian
3 месяца назад
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Version ...
CVSS3: 6.5
github
3 месяца назад
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
EPSS
Процентиль: 18%
0.00058
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-770