PT-2001-2500 · Mozilla · Bugzilla

Published

2001-09-10

·

Updated

2016-10-18

·

CVE-2001-1401

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions prior to 2.14
Description The issue allows Bugzilla users to bypass viewing permissions for confidential bugs by modifying bug id parameters in various API endpoints, including "process bug.cgi", "show activity.cgi", "showvotes.cgi", "showdependencytree.cgi", "showdependencygraph.cgi", "showattachment.cgi", and "describecomponents.cgi".
Recommendations For versions prior to 2.14, update to version 2.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the aforementioned API endpoints to minimize the risk of exploitation. Avoid using modified bug id parameters in these endpoints until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1401

Affected Products

Bugzilla