PT-2004-2539 · Mozilla · Bugzilla
Casey Klein
·
Published
2004-10-25
·
Updated
2017-07-11
·
CVE-2004-1633
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.9 through 2.18rc2
Bugzilla version 2.19 from CVS
Description
The issue allows remote authenticated users to modify the keywords in a bug. This is due to the
process bug.cgi script not checking edit permissions on the keywords field. The modification can be done via the keywordaction parameter.Recommendations
For Bugzilla versions 2.9 through 2.18rc2, restrict access to the
process bug.cgi script until a fix is available.
For Bugzilla version 2.19 from CVS, avoid using the keywordaction parameter in the process bug.cgi script until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla