{"id":"CVE-2020-29604","aliases":["GHSA-f38c-wxp6-8xjv"],"url":"https://o3.security/vulnerability/CVE-2020-29604","summary":"MantisBT Missing Authorization access check in bug_actiongroup.php","details":"An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private view status, or belonging to a private Project) via the bug_arr[] parameter. This provides full access to potentially confidential information.","published":"2021-01-29T07:15:17.873Z","modified":"2026-08-07T15:12:31.455334Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.24.4"}],"fix":null,"references":[{"type":"FIX","url":"https://mantisbt.org/bugs/view.php?id=27357"},{"type":"FIX","url":"https://mantisbt.org/bugs/view.php?id=27728"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:12:31.455334Z"}}