PT-2004-1221 · Mozilla · Bugzilla
Stefan Mayr
·
Publicado
2004-06-03
·
Atualizado
2017-07-11
·
CVE-2003-1044
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.16.3 and earlier
Description
The issue arises in editproducts.cgi when usebuggroups is enabled. It fails to properly remove group add privileges from a group that is being deleted. This allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
Recommendations
For Bugzilla versions 2.16.3 and earlier, update to a version where this issue is resolved to prevent unauthorized group additions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bugzilla