View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0023925 | mantisbt | security | public | 2018-02-02 15:16 | 2019-02-01 11:17 |
Reporter | atrol | Assigned To | vboctor | ||
Priority | normal | Severity | major | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Target Version | 2.11.0 | Fixed in Version | 2.11.0 | ||
Summary | 0023925: Site path leakage in error handler | ||||
Description | PHP errors messages are visible for end users in current master.
The error message was not visible to end users in 2.10.0. You got just a blank screen and the error was logged in web server log. Most likely it's been introduced by latest changes of error handler, see also ~58719 | ||||
Tags | No tags attached. | ||||
MantisBT: master 404a75ec 2018-02-02 21:59 Details Diff |
Fix regression that discloses file path in some errors This was introduced as part of refactoring error handler and it happens with some errors even when show_detailed_errors is set to OFF. Fixes 0023925 |
Affected Issues 0023925 |
|
mod - api/soap/mc_api.php | Diff File | ||
mod - core/error_api.php | Diff File | ||
MantisBT: master 15c7af56 2018-02-03 13:53 Details Diff |
Revert "Fix regression that discloses file path in some errors" This reverts commit d5d85f17bf934f6a13abcce69fec41171096205e. |
Affected Issues 0023925 |
|
mod - api/soap/mc_api.php | Diff File | ||
mod - core/error_api.php | Diff File | ||
MantisBT: master 2aa1c090 2018-02-03 15:22 Details Diff |
Don’t show php exceptions but log them |
Affected Issues 0023925 |
|
mod - api/rest/index.php | Diff File | ||
mod - api/soap/mc_api.php | Diff File | ||
mod - core/error_api.php | Diff File | ||
MantisBT: master 70324479 2018-02-05 20:14 Details Diff |
Fix func name typo for getting stack trace as string |
Affected Issues 0023925 |
|
mod - api/rest/index.php | Diff File | ||
mod - api/soap/mc_api.php | Diff File | ||
mod - core/error_api.php | Diff File | ||
MantisBT: master a770ccfb 2018-02-05 20:21 Details Diff |
Show exceptions in UI when show detailed errors is ON |
Affected Issues 0023925 |
|
mod - core/error_api.php | Diff File | ||
MantisBT: master b2119ce0 2018-02-05 20:24 Details Diff |
Show PHP exception in REST only if detailed errors is ON |
Affected Issues 0023925, 0025429 |
|
mod - api/rest/index.php | Diff File |