PT-2004-1221 · Mozilla · Bugzilla
Stefan Mayr
·
Published
2004-06-03
·
Updated
2017-07-11
·
CVE-2003-1044
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.16.3 and earlier
Description
The issue arises in editproducts.cgi when usebuggroups is enabled. It fails to properly remove group add privileges from a group that is being deleted. This allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
Recommendations
For Bugzilla versions 2.16.3 and earlier, update to a version where this issue is resolved to prevent unauthorized group additions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla