MantisBT allows a bugnote author to access the note's Revisions page after losing access to the parent private issue.
Disclosure of the private Issue's Id and Summary. The bugnote full revision body remains secure.
None
Thanks to Vishal Shukla for discovering and responsibly reporting the issue.
{
"github_reviewed": true,
"github_reviewed_at": "2026-05-11T19:33:10Z",
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"nvd_published_at": null
}