PT-2004-1783 · Mozilla · Bugzilla

Published

2004-07-21

·

Updated

2017-07-11

·

CVE-2004-0703

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.17.1 through 2.17.7
Description The issue concerns an unknown vulnerability in the administrative controls of Bugzilla, where users with "grant membership" privileges can grant memberships to groups they do not control.
Recommendations For Bugzilla versions 2.17.1 through 2.17.7, consider restricting the "grant membership" privilege to prevent unauthorized membership grants until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0703

Affected Products

Bugzilla