PT-2008-3620 · Mozilla · Bugzilla

Publicado

2008-05-07

·

Atualizado

2017-08-08

·

CVE-2008-2104

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla version 3.1.3
Description The issue allows remote authenticated users without canconfirm privileges to bypass the canconfirm check and create NEW or ASSIGNED bug entries. This is achieved by sending a request to the XML-RPC interface.
Recommendations For Bugzilla version 3.1.3, consider restricting access to the XML-RPC interface until a patch is available. As a temporary workaround, review and limit the creation of NEW or ASSIGNED bug entries by users without canconfirm privileges to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2104

Produtos afetados

Bugzilla