You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
By default the issue is not crossed out (if the issue is recently send/not modified)
Click the details button
It will redirect to mantisbt-2.24.3/plugin.php?page=Source/view&id=1 where the attach issue will also include. In this case my issue get resolved so the color indicator is green
If we click the issue it will just return Access Denied.
At first I get confuse if this is a default feature or not but I guess if this is not an issue please validate the type of issue (check if public/private issue)
The text was updated successfully, but these errors were encountered:
A user having Update threshold can attach *any* Issue to a Changeset,
even if they do not have access to it (i.e. private Issue), by entering
the Issue's Id.
Fixes#344
Description
This issue allows the attacker to disclose the current status of a private report by attaching it on the
attach issues
field.Repositories
Attach Issues
fieldRequest
Response
details
buttonmantisbt-2.24.3/plugin.php?page=Source/view&id=1
where the attach issue will also include. In this case my issue get resolved so the color indicator is greenAccess Denied.
At first I get confuse if this is a default feature or not but I guess if this is not an issue please validate the type of issue (check if public/private issue)
The text was updated successfully, but these errors were encountered: