Lucene search

K
freebsdFreeBSD1F0D0024-AC9C-11EE-8E91-1C697A013F4B
HistoryOct 14, 2023 - 12:00 a.m.

mantis -- multiple vulnerabilities

2023-10-1400:00:00
vuxml.freebsd.org
12
mantis
multiple vulnerabilities
guzzlehttp/psr7
dokuwiki integration
security release
maintenance release
information leakage
cve-2023-29197
cve-2023-44394
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.3 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.5%

Mantis 2.25.8 release reports:

Security and maintenance release

0032432: Update guzzlehttp/psr7 to 1.9.1 (CVE-2023-29197)
0032981: Information Leakage on DokuWiki Integration (CVE-2023-44394)

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.3 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.5%