Résumé

MantisBT: REST API unauthorized Issue status change

Détails de l’avis

A MantisBT user having $g_update_bug_threshold (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the $g_set_status_threshold config is set to a higher level (DEVELOPER by default).

Impact

Unauthorized change in Issue workflow.

Patches

https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4

Workarounds

None

Resources

Credits

Mamdouh Mahfouz (@mamdouhmahfouz)

Références