A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)
Update mantisbt/mantisbt to 2.28.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMantisBT: REST API unauthorized Issue status change affects mantisbt/mantisbt (composer). Severity is medium. A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| mantisbt/mantisbtcomposer | >=2.8.0,<=2.28.3 |
A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)
Update mantisbt/mantisbt to 2.28.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMantisBT: REST API unauthorized Issue status change affects mantisbt/mantisbt (composer). Severity is medium. A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| mantisbt/mantisbtcomposer | >=2.8.0,<=2.28.3 |
| 2.28.4 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 2.28.4 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard