{"id":"GHSA-hf4x-6h87-hm79","summary":"MantisBT may expose private issues' summaries to unauthorized users","details":"### Impact\nDue to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*.\n\n### Patches\nThe vulnerability has been fixed in MantisBT version 2.25.6. \n\n### Workarounds\nNone\n\n### Credits\nThanks to [d3vpoo1](https://github.com/jrckmcsb) for reporting the issue.\n\n### References\n- https://mantisbt.org/bugs/view.php?id=31086\n","aliases":["CVE-2023-22476"],"modified":"2024-02-16T08:20:22.774504Z","published":"2023-02-23T19:39:54Z","database_specific":{"github_reviewed_at":"2023-02-23T19:39:54Z","nvd_published_at":"2023-02-23T19:15:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-hf4x-6h87-hm79"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=31086"}],"affected":[{"package":{"name":"mantisbt/mantisbt","ecosystem":"Packagist","purl":"pkg:composer/mantisbt/mantisbt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.25.6"}]}],"versions":["2.10.0","2.10.1","2.11.0","2.11.1","2.12.0","2.12.1","2.12.2","2.13.0","2.13.1","2.13.2","2.14.0","2.15.0","2.15.1","2.16.0","2.16.1","2.17.0","2.17.1","2.17.2","2.18.0","2.18.1","2.19.0","2.19.1","2.20.0","2.20.1","2.21.0","2.21.1","2.21.2","2.21.3","2.22.0","2.22.1","2.22.2","2.23.0","2.23.1","2.24.0","2.24.1","2.24.2","2.24.3","2.24.4","2.24.5","2.25.0","2.25.1","2.25.2","2.25.3","2.25.4","2.25.5","2.3.0","2.3.1","2.3.2","2.3.3","2.4.0","2.4.1","2.4.2","2.5.0","2.5.1","2.5.2","2.6.0","2.7.0","2.7.1","2.8.0","2.8.1","2.9.0","2.9.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.25.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-hf4x-6h87-hm79/GHSA-hf4x-6h87-hm79.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}