MantisBT 1.2.16 released

Global announcements, rules, administrative notes, etc.

Moderators: Contributor, Developer

MantisBT 1.2.16 released

Postby atrol » Feb 08, 2014 4:32 am

MantisBT 1.2.16 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are strongly advised to upgrade to this release.

Unfortunately we introduced a regression http://www.mantisbt.org/bugs/view.php?id=16940 .
Don't use this version if you use the news feature of MantisBT or apply the small change that is mentioned in the issue.

The following security issues were resolved:

Cross-site scripting (XSS) issue in account_sponsor_page.php, allowing a malicious user with project manager access to execute arbitrary JavaScript code (CVE-2013-4460). Affects MantisBT 1.1.0 and later. Refer to issue http://www.mantisbt.org/bugs/view.php?id=16513 for detailed information.

SQL injection attacks through the SOAP API’s mc_attachment_get() function (CVE-2014-1608). Affects MantisBT 1.1.0a4 and later. Refer to issue http://www.mantisbt.org/bugs/view.php?id=16879 for detailed information.

Additional cases of unsanitized SQL query parameters usage were identified, potentially allowing SQL injection attacks (CVE-2014-1609). Refer to issue http://www.mantisbt.org/bugs/view.php?id=16880 for detailed information.


This release also includes many bug fixes and enhancements to the tracker and the SOAP api, as well as updated translations in many languages.

A full changelog can be found at:
http://www.mantisbt.org/bugs/changelog_ ... ion_id=183

The release can be downloaded from
http://sourceforge.net/projects/mantisb ... le/1.2.16/
Please use Search before posting and read the Manual
Use Mantis2Go to try MantisBT on Windows or to reproduce issues
atrol
Site Admin
 
Posts: 6711
Joined: Mar 26, 2008 4:37 pm
Location: Germany

Return to Announcements

Who is online

Users browsing this forum: No registered users and 1 guest