Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 570986 (CVE-2014-9759) - www-apps/mantisbt: crypto_master_salt sensitive config was disclosed via SOAP API
Summary: www-apps/mantisbt: crypto_master_salt sensitive config was disclosed via SOAP...
Status: RESOLVED FIXED
Alias: CVE-2014-9759
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [upstream/ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-05 14:31 UTC by Agostino Sarubbo
Modified: 2016-04-01 03:47 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-01-05 14:31:33 UTC
From ${URL} :

It was found that config options of crypto_master_salt was available via SOAP API, due to wrong 
spelling, since MantisBT sensitive config options were blacklisted to prevent their access via SOAP 
API.

Upstream report:

http://sourceforge.net/p/mantisbt/mailman/message/32948048/

CVE assignment:

http://seclists.org/oss-sec/2016/q1/4

After this vulnerability appeared, MantisBT was hardened to use whitelist approach instead of 
blacklisting:

https://github.com/mantisbt/mantisbt/commit/7927c275


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-07 08:28:19 UTC
Multiple vulnerabilities spread across 9 different bugs.  No movement from maintainers in over a year.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-04-01 03:47:08 UTC
Package removed